Descrizione Breve
Il trojan downloader Xombe è stato inviato, come allegato di
una e-mail, a molti indirizzi il 9 Gennaio 2004. Quando viene eseguito,
il trojan si connette ad internet , scarica un'altro trojan e si attiva
sul computer della vittima.
Descrizione Dettagliata
l trojan Xombe è stato spedito a molti indirizzi in e-mail simili
alla seguente:
From:
windowsupdate@microsoft.com
Subject:
Windows XP Service Pack 1 (Express) - Critical Update.
Window Update has determined that you are running a beta version of Windows
XP Service Pack 1 (SP1). To help improve the stability of your computer,
Microsoft recommends that you remove the beta version of Windows XP SP1
and re-install Windows XP SP1. If you cannot remove the beta version,
you should still reinstall Windows XP SP1.
Windows XP SP1 provides the latest security, reliability, and performance
updates to the Windows XP family of operating systems. Windows XP SP1
is designed to ensure Windows XP platform compatibility with newly released
software and hardware, and includes updates to resolve issues discovered
by customers or by Microsoft's internal testing team.
The maximum download size is approximately 3 MB, however the size of
the download and time required may be less for computers that have had
updates previously installed.
To minimize the download time needed for installation, setup will only
download those files which are required to bring your computer up to date.
Windows XP SP1 includes Internet Explorer 6 SP1. Anti-virus software programs
may interfere with the installation of Windows XP SP1. Please disable
anti-virus software while installing the service pack.
Just run the file winxp_sp1.exe in attach and make sure to restart your
PC after installation will be completed.
(c) 2004 Microsoft Corporation. All rights reserved. Terms of Use Privacy
Statement
Allegato E-mail
winxp_sp1.exe
Quando viene eseguito, il trojan si connette ad internet , scarica un'altro
trojan e si attiva sul computer della vittima.
Rilevazione
F-Secure Anti-Virus è in grado di rilevare il trojan con gli aggiornamenti
pubblicati il 9 Gennaio 2004:
[FSAV_Database_Version] Version=2004-01-09_01
Dettagli tecnici: Alexey Podrezov, 9 Gennaio 2004;
F-Secure Corporation
|