Discover Seattle!

General Category => Discover Seattle! => Topic started by: TehBorken on Oct 21 06 06:05

Title: Spam Trojan Installs Own Anti-Virus Scanner
Post by: TehBorken on Oct 21 06 06:05
The trojan "SpamThrough" [a href="vny!://www.eweek.com/article2/0,1895,2034680,00.asp"]takes the game to a new level[/a]. The new virus uses an anti-virus engine to remove potential 'rival' infectious code.

From the article:
"At start-up, the Trojan requests and loads a DLL from the author's command-and-control server. This then downloads a pirated copy of Kaspersky AntiVirus for WinGate into a concealed directory on the infected system. It patches the license signature check in-memory in the Kaspersky DLL to avoid having Kaspersky refuse to run due to an invalid or expired license, Stewart said. Ten minutes after the download of the DLL, it begins to scan the system for malware, skipping files which it detects are part of its own installation."