Spam Trojan Installs Own Anti-Virus Scanner

Started by TehBorken, Oct 21 06 06:05

Previous topic - Next topic

TehBorken

The trojan "SpamThrough" [a href="http://www.eweek.com/article2/0,1895,2034680,00.asp"]takes the game to a new level[/a]. The new virus uses an anti-virus engine to remove potential 'rival' infectious code.

From the article:
"At start-up, the Trojan requests and loads a DLL from the author's command-and-control server. This then downloads a pirated copy of Kaspersky AntiVirus for WinGate into a concealed directory on the infected system. It patches the license signature check in-memory in the Kaspersky DLL to avoid having Kaspersky refuse to run due to an invalid or expired license, Stewart said. Ten minutes after the download of the DLL, it begins to scan the system for malware, skipping files which it detects are part of its own installation."  
The real trouble with reality is that there's no background music.