Trojan.Downloader.Exchanger.A( TR/Crypt.FKM.Gen, Trojan Dialer.gen14 )
SINTOMI: The existence of the file CbEvtSvc.exe in the system directory (usually C:\Windows\System32).The existence of the file symavc32.sys in the drivers directory (usually C:\Windows\System32\Drivers). DESCRIZIONE TECNICA: This malware spreads by tricking users into clicking on links and executing the applications downloaded from those links. The link arrives in unsolicited bulk e-mails (SPAM) which promise explicit videos of celebrities. Currently two such e-mails have been observed:
Once installed the malware will copy itself in the system directory (C:\Windows\System32 on the default Windows XP installation) with the name CbEvtSvc.exe and register itself as a system service. After installation it contacts the original server and requests a lists of files to be downloaded through an encrypted SSL connection. Currently it downloads two additional files:
ISTRUZIONI DI RIMOZIONE: Please let BitDefender delete the infected files.ANALIZZATO DA: Attila-Mihaly Balazs, virus researcher |