Reply
Old May 19th, 2004 Top | #1
 
tdinc's Avatar
█▄█ ▀█▄ █
Joined: December 2003
Location: Sterling Heights, MICHIGAN
Posts: 3,507
Blog Entries: 19
Reputation: 2905
Power: 168

Exclamation Beware! BMP files may contain a new virus

Kaspersky Labs has detected a mass mailing of a new Trojan named Agent. Agent infects victim machines when users view graphics in BMP format.

Agent exploits a vulnerability in MS Internet Explorer versions 5.0 and 5.5 which allows malicious code to be launched on victim machines via modified BMP files. This vulnerability is a direct result of the Windows source code leak and was first detected on February 16, 2004.

Agent was mailed using spammer technology in an infected email that only contains a BMP file with a random name. The file is created especially for the Russian version of Windows 2000; the malicious code will not function on other language versions. This implies that Agent was probably created in Russia or the CIS.

Should a user open the BMP file Agent immediately connects to a remote server located in the Lybian domain zone, downloading and installing a second Trojan named Throd.

Throd is a classic spyware program. The Trojan first copies itself into the Windows system registry autorun keys and then awaits further commands. The 'master' can remotely execute various commands on the victim machine including copying data, collecting addresses from MS Outlook and turning the infected computer into a proxy server functioning as a platform for anonymous cyber crimes.

"Throd is obviously written for spammers,' comments Eugene Kaspersky, Head of Anti-Virus Research at Kaspersky Labs, 'the Trojan harvests email addresses and creates a network of zombie machines for massive spammer attacks. Once again, we see spammers and virus-writers are working hand in hand."

To date, Microsoft has not issued a patch for this vulnerability. In other words, the only protection users have is up-to-date anti-virus software. "Moreover, it is very likely that malware attacking other versions of Windows will soon appear', adds Eugene Kaspersky, 'I strongly recommend that users make sure that their antivirus software protects them from malware exploiting this particular Windows vulnerability."

Kaspersky® Anti-Virus does scan the contents of BMP files and automatically detects suspicious objects attempting to penetrate via either the Internet of email. The solution neutralizes Agent automatically and our antivirus databases have been updated to detect Throd.

Detailed descriptions of both Agent and Throd are available in the Kaspersky Virus Encyclopedia.

tdinc is offline   Reply With Quote
Old May 19th, 2004 Top | #2
 
X-Istence's Avatar
*
Joined: December 2001
Location: USA
Posts: 6,496
Reputation: 2808
Power: 220

Default

Old bug, was found when the source was leaked, was an entire story on /.

Also, it does not affect IE 6.x, or any other browser (Firefox, and Opera :P)
X-Istence is offline   Reply With Quote
Old May 19th, 2004 Top | #3
 
tdinc's Avatar
█▄█ ▀█▄ █
Joined: December 2003
Location: Sterling Heights, MICHIGAN
Posts: 3,507
Blog Entries: 19
Reputation: 2905
Power: 168

Default

Well, what can I say, A few days and a dollar short.

tdinc is offline   Reply With Quote
Old May 19th, 2004 Top | #4
 
ThePatriot's Avatar
-=[BOHICA!]=-
Joined: January 2004
Location: Pennsylvania
Posts: 1,742
Reputation: 750
Power: 127

Default

Originally Posted by tdinc
Well, what can I say, A few days and a dollar short.
Don't feel too bad, that's my life story!

ThePatriot is offline   Reply With Quote
Old May 19th, 2004 Top | #5
 
Petros's Avatar
Thief IV
Joined: May 2003
Location: Pacific Northwest
Posts: 3,038
Reputation: 1647
Power: 156

Default

Windows 98 users who never update their software better watch out!
Petros is offline   Reply With Quote
Old May 19th, 2004 Top | #6
Xie

OSNN Subscriber
OSNN Folding Team  
Xie's Avatar
- geek -
Joined: September 2003
Location: NY, USA
Posts: 5,224
Reputation: 1730
Power: 175

Default

Originally Posted by Unwonted
Windows 98 users who never update their software better watch out!
Originally Posted by tdinc
The file is created especially for the Russian version of Windows 2000; the malicious code will not function on other language versions.

tehgeek | tehgeek | geeking out to tech | IRC | *Parted Magic* | A+ Certified Professional

Xie is offline   Reply With Quote
Old May 19th, 2004 Top | #7
 
SPeedY_B's Avatar
I may actually be insane.
Joined: March 2002
Location: Midlands, England
Posts: 15,800
Reputation: 2877
Power: 310

Default

Wow, talk about specific targeting
SPeedY_B is offline   Reply With Quote
Old May 19th, 2004 Top | #8

OSNN Folding Team  
Electronic Punk's Avatar
The Last High
Joined: December 2001
Location: London
Posts: 18,510
Blog Entries: 51
Reputation: 3652
Power: 349

Default

Well the one in my thread doesn't
Free reputation for whoever does it... lol

Electronic Punk is offline   Reply With Quote
Old May 19th, 2004 Top | #9
 
rushm001's Avatar
In the beginning......
Joined: September 2002
Location: Norfolk, UK
Posts: 3,480
Reputation: 1370
Power: 165

Default

Free reputation?

rushm001 is offline   Reply With Quote
Old May 19th, 2004 Top | #10
 
ming's Avatar
OSNN Advanced
Joined: June 2003
Location: UK
Posts: 4,252
Reputation: 1160
Power: 162

Default

BMP?!
Have you heard rumours about the possibility of infections through JPG and mp3's as well?

Curent system:
Intel Quad Core 9450 | 4GB RAM | WD Raptor 36GB | nVidia 8800GT 512mb
ming is offline   Reply With Quote
Old May 19th, 2004 Top | #11
 
X-Istence's Avatar
*
Joined: December 2001
Location: USA
Posts: 6,496
Reputation: 2808
Power: 220

Default

jpg and mp3's are old news :P
X-Istence is offline   Reply With Quote
Old May 19th, 2004 Top | #12
 
ming's Avatar
OSNN Advanced
Joined: June 2003
Location: UK
Posts: 4,252
Reputation: 1160
Power: 162

Default

Originally Posted by X-Istence
jpg and mp3's are old news :P
Yes, me knowz... but does he?!

Curent system:
Intel Quad Core 9450 | 4GB RAM | WD Raptor 36GB | nVidia 8800GT 512mb
ming is offline   Reply With Quote

Reply

Bookmarks

Thread Tools

Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
BEWARE-Merry Christmas virus Dark Atheist Funny Farm 7 December 19th, 2007 8:04pm
Spammers Beware coathanger007 Green Room 9 May 17th, 2007 9:41am
Virus Passworded My Files Helppp Windows Desktop Systems 10 May 6th, 2006 1:19am
Ladies Beware! Evil Marge Funny Farm 7 April 14th, 2005 6:30pm
Car Sellers Beware rushm001 Green Room 0 January 17th, 2005 9:19pm