Unusual Malware Obtainable from Romanian Social Welfare Website

Legitimate websites that have been compromised normally deliver malicious software, which reaps monetary gains to its peddlers; however, exceptions may arise. Thus, a Microsoft customer recently sent one submission form to the software company which downloaded a few dubious files from one particular site. On examining carefully it was substantiated that the site was really hostile where the hosted malware was identified as Trojan:BAT/Delosc.A. Help Net Security published this in news on January 27, 2012.

Moreover, hosted on the domain, asistentasociala.info, the site apparently is very popular presenting e-forms, which must be completed so applicants can get "social welfare," along with directions on the way for doing it. The forms, mostly in Excel, Word and PDF formats, are provided for download that are unsurprisingly altered to EXE files having identical filenames.

Here it maybe mentioned that the icon for the malevolent files is exactly of the original that thus hides the falsity to the computer user. To be precise, soon as these malevolent .exe files are executed, they install the real, innocuous document files so that the farce remains unhindered; however, behind the screen, they install one BAT file too within the Temporary Files directory.

Apparently, while attempting at erasing folders and files, the said BAT file targets 2 software solutions that Romanian institutions mainly work with. These are 'Aplxpert,' software for document management determined with rules outlined with regards to public administration, and 'Indaco,' software which provides legal documentation services.

The BAT file then moves to erase files and folders, which have the strings such as "mono," "factur," "agr," "glob," "multi," "gami," "social," "arenda," "alocati," "asf," "vmg," "assist," "inclaz" and "lemne" on the drives such as C, D, E, F, G and H. Microsoft published this on January 26, 2012.

Nevertheless, investigators continue to examine the malware, while hitherto its purpose appears pretty distinct. They also advise Internauts for being careful when they download files whilst watching for those which display a file extension different from the icon for it. Finally, like always, it's very important to activate anti-virus software for safeguarding one's PC from the above type of threats.

» SPAMfighter News - 04-02-2012

 

All SPAMfighter products offer a free trial!

SPAMfighter box shot

SPAMfighter is a free spam filter for Outlook, Outlook Express,Windows Mail, Windows Live Mail and Thunderbird.

SLOW-PCfighter

Optimize your Slow PC for better performance. Try FREE scan now

Full disk or slow disk?
Disk space recovery
and disk optimization. Try FULL-DISKfighter free


Spam Filter for Exchange Server

SPAMfighter Exchange Module is a Spam filter for Exchange server - Free 30 days trial.

Remove spyware

Remove Spyware with SPYWAREfighter - Free 30 days trial

Antivirus software

Antivirus software for your Windows PC - Free 30 days trial

<<<  >>> 

Compatible with Windows 7

Works with Windows Vista

SPAMfighter is

Microsoft Gold Certified Partner

Intel Software Partner