Results 1 to 3 of 3

Thread: New Trojan/Spyware (might hijack/rewrite DNS info)

  1. #1
    Member GT500's Avatar
    Join Date
    Nov 2005
    Location
    Indiana, USA
    Posts
    70

    Default New Trojan/Spyware (might hijack/rewrite DNS info)

    I just found a link in the server-side stats for my website which showed that a webpage about some video was linking to my website. When I followed the link to see what this webpage was about, I found what looked to be a YouTube video embedded in the page, but a dialog poped up complaining that I needed to download a new ActiveX control to view the video. It looked like a dialog you would see in IE6 on Windows XP, but I'm using Opera 9.23 on Linux, so it was obviously JavaScript. The scripting on the page was also very persistent, and each time I tried to cancel the download, it would just start it back up again (eventually causing Opera to hang, and me to be forced to kill the Opera processes in my KDE SystemGuard). While I did not take a look at the scripting, or try the site out in any other browser, my guess is that it will also exploit security flaws in Internet Explorer to automatically install itself on visitors computer, and do so without their knowledge.

    The URL of this website is below. Please note that this link is for the Spybot team only, and no one but you can be held responsible for the damage done to your computer if you follow this link, and your system gets infected.
    "http://www.volny.cz/alexpics/video.html" (quotes are to prevent auto-linking)

    The file that was downloaded was called "VideoAccessCodecInstall.exe" and it was identified by ClamAV as "Trojan.Dropper-2259" and by AntiVir as "TR/DNSChanger.CA.9". Kaspersky Labs just e-mailed me back to confirm that this really is a new virus, and that they have named it "Trojan-Downloader.Win32.Zlob.byx".

    If you need any more info, then just let me know.

    If this would have been better reported via e-mail or an online form, then let me know, and I will make sure to use it next time.

  2. #2
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,961

    Default

    Hello.

    Thank you for the quotes around the link.

    If you have the file/s, please do zip and send to: detections(AT)spybot.info (Replace AT with @)

    Add any information you may have to that email.

    Best Regards.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

  3. #3
    Member GT500's Avatar
    Join Date
    Nov 2005
    Location
    Indiana, USA
    Posts
    70

    Default

    I hope that GZipping the virus I e-mailed didn't cause you any trouble. I don't normally use ZIP for single files on Linux, and I've found that most archive managers can uncompressed a GZipped file.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •