Security Bytes

Apr 7 2010   1:03PM GMT

New Trojan masquerades as Adobe update



Posted by: Robert Westervelt
scareware, malware, Rogue Antivirus

If victims are tricked, the Trojan downloads other malicious files designed to enable attackers to remotely steal data.

TrendLabs engineers have discovered a new trick that uses a phony Adobe update to install a Trojan on victim’s machines.

An unsuspecting victim can fall prey to the trick by visiting a website hosting the malicious code. The engineers, part of Trend Micro’s research team discovered cybercriminals using the scheme to push a Trojan, Troj_Faykdobe, onto victims machines.

“This malware bears identical icons and version details to an Adobe update, which enables it to bypass antivirus software and system analysts, and to trick users into believing that it is legitimate,” wrote Oscar Abendan of Trend’s technical communications team in the TrendLabs Malware Blog.

Analysis of the Trojan was conducted by TrendLabs threat response engineer, Jessa De La Torre. According to De La Torre, the Trojan drops other malware that terminates certain processes and contacts a remote server for orders. It can be controlled by cybercriminals remotely to steal account credentials and other data unknowingly from the victim.

The Trojan does not appear to affect users of Microsoft Vista or Windows 7. It runs on Windows 98, ME, NT, 2000, XP, and Server 2003.

Back in October, the notorious Koobface botnet spread on Facebook using a template spoofing Adobe’s Flash updater embedded within a fake YouTube page. Like the attack technique above, cybercriminals are using legitimate websites to host their malicious code.

The technique of spoofing update utilities has long been used and is growing in popularity as part of the rogue antivirus trend. The scareware uses coding to appear is if it is part of Windows malware threat detection.

Comment on this Post


You must be logged-in to post a comment. Log-in/Register

Traderdonald  |   Feb 1 2011   9:10AM GMT

Wow! what an idea ! Nice
my blogs: master cleanse | cityville cheats


 

Wangsally  |   Mar 18 2011   9:17AM GMT

Good read. There is currently quite a lot of information around this subject on the net and some are most definitely better than others. You have caught the detail here just right which makes for a refreshing change – thanks
Karaoke mixer
Water Pumps
Callaway X-24 Irons


 

Wangsally  |   Mar 18 2011   9:18AM GMT

Great article. I like your post. I will keep visiting this blog very often. It is good to see you verbalize from the heart and your clarity on this important subject on trees can be easily observed.
louis vuitton handbags
mbt sport
beats headphones


 

Wangsally  |   Mar 18 2011   9:18AM GMT

I was very pleased to find this site.I wanted to thank you for this great read!! I definitely enjoying every little bit of it and I have you bookmarked to check out new stuff you post.
Titleist AP2 Irons
lacoste shoes
Moncler Jacket


 

Rachmadek  |   Apr 1 2011   5:40PM GMT

Yes, so we must be careful if the adobe automatic update. Then, still update your anti virus. College Scholarships | Job Vacancies | Global News


 

Rgmoon  |   Apr 2 2011   7:31AM GMT

Trojan has always been providing innovative ideas and this is another fantastic update from this software. thanks for providing such valuable info and keep providing us such updates in future as well.
Catholic TV


 

5m  |   Apr 4 2011   10:26PM GMT

ot of information around this subject on the net and some are most definitely better than others.

1 3 dimethylamylamine


 

Supybot  |   Apr 12 2011   8:59AM GMT

Finally, an issue that I am passionate about. I have looked for information of this caliber for the last several hours. Your site is greatly appreciated.
Computers and Technology


 

Inchanto  |   Apr 14 2011   11:14PM GMT

interesting article. my blogs: chat libera | chat amici


 

Deesydia  |   Apr 15 2011   12:48PM GMT

Well, with the technical advances made by these hackers, the user should try to be more careful with his / her Internet browsing. Otherwise, he / she will end up a victim of these malicious hackers.

Dee - <a href="http://woodworkingplansdiy.org/" rel="nofollow">Woodworking Plans</a>


 

Sarah532  |   Apr 25 2011   10:21AM GMT

It seems like you’ve gathered yourself a pretty good following now. I’m pleased to see it.

[medical aid quotes | [a href="http://www.hospitalplans.org.za]hospital plan | [a href="http://www.carinsurancequotes.org.za]car insurance quotes


 

Sarah532  |   Apr 25 2011   10:24AM GMT

It seems like you’ve gathered yourself a pretty good following now. I’m pleased to see it.

medical aid quotes
car insurance quotes
loans


 

Mediahuset  |   Apr 27 2011   10:10AM GMT

Business

I am happy to find this post Very useful for me, as it contains lot of information. I Always prefer to read The Quality and glad I found this thing in you post. Thanks for sharing


 

Sarah532  |   Apr 28 2011   6:13PM GMT

Took me time to read all the comments, but I really enjoyed the article. It proved to be Very helpful to me and I am sure to all the commenters here! It’s always. <a href="http://www.stretchmarksremovel.com" rel="nofollow">how to get rid of stretch marks</a>


 

Sidkof123  |   Apr 28 2011   7:26PM GMT

I will always give a nice thrust look in to you from my bookmark feed.Coffee I don’t actually comment and don’t like to spend time in typing the comment. But here I have to do this because this deserves a good like. Purchase concert tickets and enjoy music..


 

Rounese  |   May 1 2011   3:18PM GMT

I would like to thank you for The Effort You Have Made in writing this article. I am Hoping The Same best work from you in the Future as well. Fact in your creative writing Abilities has Inspired me to start my own blog now BlogEngine. The blogging really IS ITS Spreading wings rapidly. Your write up Is A Fine Example of it.obat asam urat


 

Sarah532  |   May 3 2011   2:04PM GMT

Took me time to read all the comments, but I really enjoyed the article. It proved to be Very helpful to me and I am sure to all the commenters here! It’s always nice when you can not only be informed, but also entertained! I’m sure you had fun writing this article. how to get pregnant - water softener - how can i get taller


 

Garfieldodell  |   May 7 2011   11:11AM GMT

I’ll be visiting your site again to gather some more valuable information.
My blog: how to know if a girl likes you | how to get taller


 

Sarah532  |   May 11 2011   4:08PM GMT

This is such a great resource that you are providing and you give it away for free. I enjoy seeing websites that understand the value of providing a prime resource for free. I truly loved reading your post. Thanks
personal loans
outdoor lighting
furniture removals


 

Sarah532  |   May 11 2011   4:10PM GMT

Howdy. Very important job. I would not expect this on a Wednesday. It is a great account. Provides Many thanks!
car rental | insurance companies


 

Rgmoon  |   May 12 2011   3:52AM GMT

Nice to read about this new innovation. This post help us to increase our knowledge regarding IT and its products. Thanks for sharing such valuable info here.
Craigslist Salem


 

87654  |   May 12 2011   2:39PM GMT

This malware bears identical icons and version details to an Adobe update,which enables it to bypass antivirus software and system analysts,and to trick users into believing that it is legitimate.felizaniversario


 

TomGoodman  |   May 13 2011   2:07PM GMT

First of
all, I am grateful to the college students who so willingly shared their own
stories, the essays they wrote, and their experiences about the entire college-
search process in general—and their application efforts in particular.

    http://www.bestessayhelp.com

custom essay


 

TomGoodman  |   May 13 2011   2:10PM GMT

Most schools place a fairly significant emphasis on the quality of the
essay.

custom essay


 

Sidkof123  |   May 14 2011   5:44PM GMT

Trojan has always been to offer innovative ideas and this is another fantastic update of this software. thank you for providing valuable information, and we continue to provide these updates in future.
antique
collectibles


 

87654  |   May 17 2011   4:59AM GMT

If you have Adobe Reader installed on your machines (and most users do,since it’s the most popular PDF reader),you need to be aware of a new Trojan that represents itself as an Adobe update,with identical icons and version details that can even circumvent antivirus software.frases para orkut


 

87654  |   May 17 2011   8:14PM GMT

this trojan also imitates the icons and versions of the targeted programs. For example, checking the version information on the fake AdobeUpdater. <a href="http://jogosonline9.org/" rel="nofollow">jogos online</a>


 

87654  |   May 17 2011   8:16PM GMT

this trojan also imitates the icons and versions of the targeted programs. For example, checking the version information on the fake AdobeUpdater. jogos online


 

Mojo33  |   May 18 2011   11:31AM GMT

I am very interested for this post.This site is so helpful. So I want some information for sharing this side with some of my friend. Thanks for sharing the information in this article.This is such a great resource that you are providing and you give it away for free.
Pdf search engine


 

Nehaljames1  |   May 18 2011   9:42PM GMT

Article is very nicely written and I am happy to find so many useful information here in the post, thanks for sharing it here. I hope you will adding more !

[ULIST=http://www.organicspiceblend.com]herbal spice


 

Nehaljames1  |   May 18 2011   9:43PM GMT

Article is very nicely written and I am happy to find so many useful information here in the post, thanks for sharing it here. I hope you will adding more !

herbal spice


 

Theqavish  |   May 19 2011   11:13PM GMT

Colour contrast and brightness of the digital picture frames are controllable. With these features of the Nix digital photo frames even pictures taken in dim light will show up beautifully on the digital picture frame by Nix.
digital frame


 

Sidkof123  |   May 21 2011   7:12PM GMT

The Trojan is a nasty one, called Troj Faykdobe, that installs malware that can be used to send passwords and other credentials to a remote server. The good news is that it apparently doesn’t affect Vista and Windows 7. The bad news is that there are still plenty of XP computers out there that are vulnerable. Read more about it here
recados para orkut


 

Theqavish  |   May 23 2011   10:47AM GMT

. I have looked for information of this caliber for the last several hours. Your site is greatly appreciated.
Designer Bracelets


 

Ahmadferi  |   May 24 2011   4:35AM GMT

Considerably, this post is really the sweetest on this notable topic. I harmonise with your conclusions and will thirstily look forward to your incoming updates. Saying thanks will not just be sufficient, for the phenomenal clarity in your writing. I will directly grab your rss feed to stay informed of any updates. Admirable work and much success in your business dealings!  Please excuse my poor English as it is not my first tongue.

hobbs shoes


 

PeterSmithon  |   May 24 2011   9:04AM GMT

It’s good that the Trojan does not appear to affect users of Microsoft Vista. I’ve just installed it! custom essays


 

Rounese  |   May 24 2011   1:36PM GMT

the article is very entertaining. it gives us new ideas and prospectives to help widen our knowldeged.i will be glad to share this site to other people.thanks for the good and amazing post…many people will surely liked this.Casinos Review


 

Sarah532  |   May 24 2011   7:10PM GMT

This is a very great post. I will print out the post and read it carefully again. Thanks refinancing home mortgages - home loans - wholesale wedding jewelry - wholesale jewelry - office window treatments - window treatments


 

Dfdfffff  |   May 27 2011   9:01PM GMT

Article is very nicely written and I am happy to find so many useful information here in the post, thanks for sharing it here. I hope you will adding more !

Online casinos games
Top online casinos


 

Theqavish  |   May 28 2011   1:11AM GMT

really say a word that describes the credibility it gives. It is precise in its point and it does convince the interest of the readers. Well I do know competition is tough but this site leaves no doubt as to its goal. That’s one reason why no wonder it draws attention to every visitor all over the world! Continue the good deed guys! You’re truly building your name to this wise and competitive world! Keep going positively!

stride rite coupons


 

Sarah532  |   May 28 2011   11:02AM GMT

There is nothing that touches these articles for just lazing around at home….
liposomal glutathione
glutathione wholesale


 

Darrensy  |   Jun 5 2011   9:34AM GMT

I was very pleased to find this web-site.I wanted to thanks for your time for this wonderful read!! I definitely enjoying every little bit of it and I have you bookmarked to check out new stuff you blog post.
Estudiar ingles en el extranjero


 

Fullbet  |   Jun 23 2011   12:08AM GMT

The positive comments and do well wishes are very motivational and greatly appreciated. New Bonus


 

Wishy234  |   Jun 23 2011   4:00AM GMT

That’s why it’s alway good to have some type of antivirus to slow down or get rid of the trojan, good post.
razor drifter go kart | razor quad


 

Garys  |   Jun 23 2011   10:06AM GMT

Yes, and now there is a new variant of this virus on the web.

Golf Simulator


 

Nersinhu  |   Jun 23 2011   8:20PM GMT

Thanks for the info on this virus and keep it up.
<a href="http://sonynx810.org/" rel="nofollow">Sony NX810</a>


 

NickD  |   Jun 23 2011   10:26PM GMT

It is really interesting that Trojan does not effect Windows 7. Maybe, it is just the question of time …(?). Usually that happens sadly.

—————————————————

arnica gel|arnica gel review


 

Jhajs  |   Jul 4 2011   11:01PM GMT

Wow! after reading this post I think I can reduce my fats if I can control on my dite. Because I dont have a time for exercise. Thanks for sharing it with us.
head lice


 

Ytpl22  |   Jul 6 2011   11:55AM GMT

YTPL houses a capable and result oriented team of professionals and managers who can assist you with a wide range of solutions ranging from ERP implementations to email campaign management.


 

Dorothy456  |   Jul 18 2011   6:58PM GMT

I am currently searching for ways in which I could enhance my knowledge in this said topic you have posted here. It does help me a lot knowing that you have shared this information here freely.
<a href="http://www.angelprintsultrasound1.com/" rel="nofollow"> 3d4d ultrasound </a>|<a href="http://www.angelprintsultrasound1.com/" rel="nofollow"> 3d ultrasounds </a>


 

Dorothy456  |   Jul 18 2011   7:00PM GMT

I am currently searching for ways in which I could enhance my knowledge in this said topic you have posted here. It does help me a lot knowing that you have shared this information here freely.3d4d ultrasound


 

KathrinRich  |   Jul 20 2011   6:40AM GMT

Celebrities must restore their hair. They are the best character i have seen…..
i like these characters..i often search on celebrity hair transplant and hair transplant in Dubai.
Thanks for sharing dear…


 

KathrinRich  |   Jul 21 2011   12:13PM GMT

I keep my ideals, because in spite of everything, I still believe that people are really good at heart.I found your web page from aol and it is informative. Thanks for offering such an informative post!!
website design company perth


 

Kathrin  |   Jul 25 2011   2:34PM GMT

The maintenance and promotion of health is achieved by different combination of physical, mental and social well being, and sometimes called the “triangle of health.” Health is a positive concept emphasizing social and personal resources, as well as physical capabilities.
Natural vitamins supplements


 

Xiaoxiao729  |   Jul 29 2011   9:26AM GMT

I am happy to find your distinguished way of writing the cardboard balers post. Now you make it easy for me to understand and implement. Thanks for sharing with us.plastic baler


 

KathrinRich  |   Aug 27 2011   12:53PM GMT

As usual i am searching some useful information, immediately i found this post and gain some useful information great work such a great brain to use.
see [B]Free Classified Ads


 

Anne123  |   Aug 30 2011   8:43AM GMT

Amazing post..nice content you have there very informative and i enjoyed reading it!I have saved this webpage and I truly intend on visiting the site in the upcoming days. Artisan Furniture Console


 

Dorothy456  |   Sep 15 2011   11:46AM GMT

You got a absolutely advantageous blog. I accept been actuality account for about an hour. I am a newbie and your success is actual abundant an afflatus for me.
<a href="http://www.dailyads.pk/" rel="nofollow">classified ads Pakistan</a>


 

Dorothy456  |   Sep 15 2011   11:52AM GMT

Usually I do not column comments on blogs, but I would like to say that this blog absolutely affected me to do so! Thanks, for a absolutely nice read.
classified ads Pakistan


 

Betcafeo  |   Sep 19 2011   8:04PM GMT

Very useful analyze, I’ve made some bets on them this season! Thanks for helping me too see the situation objective. And hey, don’t be sad for the results, it could be worse anytime! [a href="http://www.bonus-betting.com/" title="bonus betting">bonus betting and [a href="http://www.bonus-betting.com/free-betting-tips/" title="free betting tips">free betting tips


 



Daanga  |   Sep 29 2011   9:45PM GMT

Some people just have too much time on their hands to create such trojans to use malicious tactics to do their business. If there was only a way to get these guys to focus there talents on better things.
water softeners


 

Tapori2010  |   Oct 4 2011   3:33PM GMT

Thanks for sharing such great information.
Cheap Car Insurance in Florida
<a href="http://www.souplantationcoupons2011.net" rel="nofollow">souplantation coupons 2011</a>
<a href="http://www.souplantationcoupons2011.net" rel="nofollow">souplantation coupons</a>


 


Kathrin  |   Oct 10 2011   1:16PM GMT

I can not stop reading this. And ’so fresh, so full of information, I do not know. I’m glad that people actually write the smart way to show the different sides of him.
doctor ratings and reviews
find doctors list
doctor reviews by patients


 

Xiaoxiao729  |   Oct 12 2011   3:26AM GMT

It is always better to go for the injection molding company that can provide you with excellent varieties of China garlic!


 

Webseo  |   Oct 20 2011   6:49PM GMT

One of your options on where to buy steroids is your local pharmacy. If you’re under medication for a specific type of ailment such as asthma or cancer, your doctor is more likely to prescribe them as a course of treatment.


 

Simpson2011  |   Oct 22 2011   1:49PM GMT

I like to recommend this post . I am very much happy to find this blog update. Thanks and I think you a good stuff of writing.
Reverse Osmosis


 

SabrinaSch  |   Oct 24 2011   1:13PM GMT

I will always give a nice thrust look in to you from my bookmark feed.Coffee I don’t actually comment and don’t like to spend time in typing the comment. But here I have to do this because this deserves a good like,.
Outback Steakhouse coupons
Ruby Tuesday coupons
Cascade coupons


 

Sarah532  |   Oct 30 2011   5:16AM GMT

Hello Guru, what entice you to post an article. This article was extremely interesting, especially since I was searching for thoughts on this subject last Thursday.
houses for sale in centurion | furniture removals | smokeless cigarettes


 

Sarah532  |   Oct 30 2011   5:19AM GMT

Hi I attempted to sign up to your RSS and the link seems to be broken. How can i get around this?
how can I get taller | best way to lose weight


 

Maryagirl  |   Nov 20 2011   4:50AM GMT

This is New Trojan masquerades as Adobe update is the stuff who attack all the resources of The Walking dead Season 2 Episode 7 and the very good news to know here is that they are involve from so much entertainment around the globe in the cooperation of AMC


 

Simpson2011  |   Dec 28 2011   5:52AM GMT

Lots of thanks for another valuable post. I just found your website a few days ago and I have been reading through it regularly. I really delight in reading your posts
Regards
Metaphysical Store


 

Regeniaparsons  |   Dec 31 2011   9:52AM GMT

Adobe, Microsoft and others never realized they would have to become security companies to protect their marketshare. The future in IT is much more volatile with the onslaught of malware writers proliferating at an exponential rate.
legal herbal incense


 

Jameskmoore  |   Feb 2 2012   7:29AM GMT

I appreciate your efforts to make a good discussion here on this topic. It brings possibilities to find and move with some new ideas.

All the best

best essay writing service