Troj_Dloader-CHU is a Trojan that arrives as an attachment to spammed email messages. Upon execution, it connects to the Web site: http://life{BLOCKED}o.za/capetownday5.gif to download the file BOOT.OLD in the hardcoded location C:. However, as of this writing, the said Web site is inaccessible.
It also connects to the Web site: http://www.gobe{BLOCKED}queta.gov.co/images/c655.gif to download the file AUTOEXEC.EXE in the hardcoded location C:. The said file is detected by Trend Micro as TROJ_HAXDOR.Q.
Its download routine increases the risk of acquiring more malware threats on the affected computer.
wawadave:: 7. 3/15: Dloader-CHU Trojan Arrives as Attachment Troj_Dloader-CHU is a Trojan that arrives as an attachment to spammed email messages. http://groups.msn.com/wawadave/virustrojinetc.msnw?action=get_message&mview=0&ID_Message=1624&LastModified=4675564575348995082HOME |
Pre-Article:3/15: Elf-Kaiten-AJ an Executable Linux File Next-Article:ADIC Goes Down Under for De-Duplication
|