TROJ_DLOADER.RFQ |
|
| BugsAlert Home > TROJ_DLOADER.RFQ | |
|
To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below. This Trojan may be downloaded from a certain remote site(s). It may be downloaded unknowingly by a user when visiting malicious Web site(s). It creates a registry key as part of its installation routine. It uses the following icon related to Macromedia Flash Player to trick users into thinking that it is a legitimate file:
Upon execution, this Trojan displays the following fake message box to trick unsuspecting users into thinking that it fails to execute:
When a user clicks on the OK button, it connects to several Web sites to alert a remote malicious user. It drops files that are all detected by Trend Micro as TSPY_BANCOS.ABL. The said dropped files are then executed, then searches for the folder C:\Arquivos de Programas on the affected system where TROJ_BANKER.PXN is dropped. An error message is then displayed if the said folder is not found. Otherwise, it creates the folder PLUGIN under the folder C:\Arquivos de Programas. It also drops non-malicious files. As a result, routines of the dropped files are exhibited on the affected system. Original Source: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_DLOADER.RFQ Learn more about TROJ_DLOADER.RFQ |
|
| Tags: troj dloader.rfq | |
Related Items |
|
|
Firefox Extension Blocks Dangerous Web attack
|
|
|
FrSIRT - Zilab Remote Console Server Remote Denial of Service Vulnerability
|
|
|
Microsoft Security Advisory (947563): Vulnerability in Microsoft Excel Could Allow Remote Code Execution
|
|
|
Web Wiz Forums Directory Traversal Vulnerabilities
|
|
|
CVE-2008-1974 (Groupware Webmail Edition)
|
|
|
MxBB Portal "page" SQL Injection Vulnerability
|
|
|
Bugtraq: rPSA-2008-0088-1 am-utils
|
|

