Malware City/Blog/

May
14
Filed Under:
VIRUSES DESCRIPTIONS

From E-mail Attachment to Rogue AV

14 May 2010
The postman may ring twice, but Oficla does it thrice. A simple e-mail attachment opens the way for Trojans and rogue AV on unprotected PCs.

 

Trojan.Dropper.Oficla.O usually spreads via an e-mail attachment hidden behind a fake Microsoft® Office® Word Document icon for credibility. Upon execution, Trojan.Dropper.Oficla.O drops a dll file (dynamic link library)in the %temp% folder, which will also be copied afterwards in the %system% folder under a random name such aspgsb.lto (detected as Gen:Variant.Oficla.2).

The dll is injected into the svchost.exe process, followed by the deletion of the Trojan. In order to ensure its launch at each system startup, the Trojan modifies the following registry key: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]  Shell = Explorer.exe rundll32.exe random_dll random_api - where random_dll and random_api may look like a random string combination similar to: pgsb.lto csxyfxr.

The download component is its payload: the dll dropper tries to connect to a specific list of URLs, usually hosted in Russia, from where it will retrieve and automatically install a secondary piece of malware -Trojan.Downloader.ABBL.  As soon as the new downloader has successfully infected the system, it opens the door to a rogue security solution advertised as Security Essentials 2010 and detected by BitDefender®as Trojan.FakeAV.KZD.

security essentials 2010

Once the Rogue AV is “successfully” installed, additional changes are made to the registry  in order for Internet Explorer’s phishing filter and the Windows Task Manager (to prevent the user from killing its process) to be disabled. Moreover, the rogue automatically executes itself upon every Windows boot-up.

security essentials 2010

In order to stay safe, BitDefender® recommends that you download, install and update a complete antimalware suite with antivirus, antispam, antiphishing and firewall protection and to manifest extra caution when prompted to open files from unfamiliar locations.

Information in this article is available courtesy of BitDefender virusresearcher Ovidiu Vişoiu.




Loredana sees in BitDefender a new challenge and a fresh approach to her professional development. Her enthusiasm, curiosity and, of course, lots of research, are some of the features that make her a competitive player in the security industry.

Comments:

sleep number beds said on Oct-20-2011 05:34

E-mail, to promote the use, because it really is very easy to support the support.

louis vuitton outlet said on Feb-6-2012 01:02

Almost no one can resist the temptation of LV Bags.There established many online louis vuitton outlet recently with the aim of making people's shopping more convenient.The shiny brass hardware makes it resistant and the natural cowhide leather trim matches everthing in your wardrobe. No question the discount louis vuitton bags are your first choice.

Comment on this

Name:

Email:

Website:

Your email adress will not be published.