Advanced Search
 Advanced Search
Home News Enterprise Developer
Enterprise
 Enterprise News
 Mobility
 Networking
 Security
 Storage
 ERP
Enterprise Connect
SMB Forum
Magazines
  Dataquest
  PCQuest
  Voice&Data
  Global Services Media
  Living Digital
  DQ Channels
  DQ Week
CIOL Events
  EC Awards
  SMB Awards
About CIOL

Custom Site
  • Web Threat Protection from Trend Micro
  • HP IT Service Management

Specials
  Integration of IT Assets: reality check
  Security Solution for SMBs
white papers
Enterprise > Security > News
Panda Software alerts on virus
This week report on viruses and intruders highlights the RuSpy.A, Tervserv.A and Banker.DZO trojons malicious code details
Tuesday, August 08, 2006
Previous Articles >>
Security, Defence driving IT expenditure
McAfee debuts security research journal 'Sage'

MADRID: Panda Software’s weekly report on viruses and intruders alerts on the new dynamic influencing malware creators. The three examples of malicious code detailed in the report are aimed at spying, hijacking computers and stealing bank details.

RuSpy.A is a Trojan that obtains user names and passwords for a range of programs including ICQ, Internet Explorer, Mozilla, Outlook and The Bat!. This information is then sent to the creator in an email message.

To avoid detection, it tries to terminate several processes belonging to security tools (antivirus programs and files). This however is not effective against Panda Software's TruPrevent Technologies and the auto-protection systems of Panda solutions.

As well as sending out the information mentioned before, it tries to download the file XINCH.EXE from a web page and creates shortcuts to several websites (all with Russian "ru" domains), and alters the Internet home page on the infected system.

Another widespread fraud technique is to hijack computers. This is what the Tervserv.A backdoor Trojan does. It connects to a website in order to receive remote commands, such as instructions to download and run files that give the attacker complete control over the compromised computer.

Finally, this week's report highlights the Banker.DZO. This is a Trojan that monitors Internet traffic generated when a user accesses the web pages of Banco de Brasil, Bradesco, CEF, GERENCIADOR, Itau and Brad.Juridico.

When an infected user opens one of these pages, Banker.DZO displays a false login page in order to obtain the user name and password for accessing accounts. This information is then sent to the creator in an email message. The information compiled is quite extensive, ranging from the particular bank or branch of the user to the password or even the secret password reminder question.

© CyberMedia News
  Email this article   Print this article
Top Stories of the Day
Ericsson to host multimedia services for BSNL
Optical Components market registers negative growth
DoT to set up 3 Telecom CoE in 2007
Ericsson to host multimedia services for BSNL
Indyarocks.com, the new Social Networking Portal
 


IBM developerWorks


RSS Feeds | 10th Anniversary Special | Search | Opt-In Newsletters | Slide Show | White Papers | Custom Site
Specials | News Makers | Product News | Security | Storage | Open Source | Operating System | Tutorials
+ Worth a click +
PCQuest | Dataquest | Voice&Data | Living Digital | DQ Channels | DQ Week | Global Services Media | CyberMedia Events
Cyber Astro | CyberMedia Digital | CyberMedia Dice | CyberMedia | BioSpectrum | BioSpectrum Asia

About CIOL | Awards | Media Kit | Sitemap | Contact Us | Help | Write for CIOL | Jobs@CIOL | Privacy Policy
Copyright © CyberMedia India Online Ltd.