United Kingdom
  • UK Support
  • My Account
  • Renewal Centre

Bitdefender®

  • Home
  • Home Users
  • Small Business
  • Corporate Business
  • ISPs
  • News
  • About Us
  • Partners
  • Home
  • Company
  • Press Center
  • Malware exploit linked to Adobe PDF reader, tops...
News
  • News Archive
  • Press Materials
  • Upcoming Events
  • Multimedia
  • Stay Tuned
  • Contact Us
Tools and Resources
Find out more
  • Free Online Virus Scanner
  • Renew Product Licence
  • Download Trial Versions
  • Download Datasheets
January 2010

Malware exploit linked to Adobe PDF reader, tops BitDefender’s top ten e-threats report for December


A generic detection which deals with specially crafted PDF files exploiting different vulnerabilities found in Adobe PDF Reader’s Javascript engine has topped BitDefender’s top ten e-threat report for December.


Called Exploit.PDF-JS.Gen, this device is designed to execute malicious code on the victim’s computer. Upon opening an infected PDF file, a specially crafted Javascript code triggers the download of malicious binaries from remote locations.

The second highest e-threat in BitDefender’s December listing is Trojan.AutorunInf.Gen. This is a generic mechanism to spread malware using removable devices such as flash drives, memory cards or external hard-disk drives. Win32.Worm.Downadup and Win32.TDSS are two of the most famous families of malware to use this approach to trigger newer infections.

Trojan.Clicker.CM is in third place. This is mostly found on websites hosting illegal applications such as cracks, key generators and serial numbers for popular commercial software applications. The Trojan is mostly used to force advertisements inside the users’ browser in order to boost their advertisement revenue.

Fourth is Win32.Worm.Downadup.Gen. Relying on the Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability (MS08-67), this worm spreads on other computers in the local network and restricts users’ access to Windows Update and security vendors’ web pages. Newer variants of the worm also install rogue antivirus applications, among others.

Trojan.Wimad.Gen.1, comes fifth, mostly exploits the capability of ASF files to automatically download the appropriate codec from a remote location in order to deploy infected binary files on the host system. The ASF format will store data in either WMA (Windows Media Audio) or WMV (Windows Media Video) formats, which are mostly to be found on Torrent websites. When played locally, the specially-crafted WMV file would allegedly attempt to download a “special codec”, which is in fact a malicious binary hosted on a third-party website.

Sixth place is taken by Win32.Sality.OG. This malicious e-threat is a polymorphic file infector that appends its encrypted code to executable files (.exe and .scr binaries). It deploys a rootkit and kills antivirus applications running on the computer so as to hide its presence on the infected machine.

Trojan.Autorun.AET, a malicious code spreading via the Windows shared folders, as well as through removable storage devices, is in seventh position. The Trojan exploits the Autorun feature implemented in Windows for automatically launching applications when an infected storage device is plugged in.

In eighth position is Worm.Autorun.VHG. This is an Internet /network worm that exploits the Windows MS08-067 vulnerability in order to execute itself remotely using a specially crafted RPC (remote procedure call) package (an approach also used by Win32.Worm.Downadup).

Win32.Worm.Downadup.B is in ninth position. It is a variant of Win32.Worm.Downadup with similar functionality, except for the fact that the number of blocked AV URLs is lower. Also, this is one of the least dangerous variants, as it comes with no malicious payload.

Trojan.Script.236197 concludes BitDefender’s top ten e-threats list for December. This obfuscated JavaScript file forces small pop-up windows disguised as MSN Messenger alerts when the user visits an adult website. The ads, served through advertising service DoublePimp, look like a real-time conversation with a woman allegedly located in the same area as the user’s ISP.

BitDefender’s December 2009 top ten e-threat list includes:

1. Exploit.PDF-JS.Gen12.04
2. Trojan.AutorunINF.Gen8.15
3. Trojan.Clicker.CM7.90
4. Win32.Worm.Downadup.Gen5.85
5. Trojan.Wimad.Gen.14.57
6. Win32.Sality.OG2.65
7. Trojan.Autorun.AET1.97
8. Worm.Autorun.VHG1.65
9. Win32.Worm.Downadup.B1.25
10.Trojan.Script.2361971.08
OTHERS52.85


To stay up-to-date on the latest e-threats, sign-up for BitDefender’s RSS feeds here.

BitDefender will be participating at Infosecurity Europe 2010, the No. 1 industry event in Europe held on 27th – 29th April in its new venue Earl’s Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk




* * *

About BitDefender®
BitDefender is the creator of one of the industry's fastest and most effective lines of internationally certified security software. Since its inception in 2001, BitDefender has continued to raise the bar and set new standards in proactive threat prevention. Every day, BitDefender protects tens of millions of home and corporate users across the globe - giving them the peace of mind of knowing that their digital experiences will be secure. BitDefender solutions are distributed by a global network of value-added distribution and reseller partners in more than 100 countries worldwide. More information about BitDefender and its products are available at the company’s security solutions press room. Additionally, BitDefender’s www.malwarecity.com provides background and the latest updates on security threats helping users stay informed in the everyday battle against malware.



© 2010 BitDefender

  • Site Map
  • Legal Terms
  • Site Feedback
  • Global Sites
  • Privacy Policy

For Home Users

  • BitDefender® Total Security 2011
  • BitDefender® Internet Security 2011
  • BitDefender® Antivirus Pro 2011
  • BitDefender 2011 Product Comparison

For Small Business

  • For Small Business
  • BitDefender® Small Business Security for Desktops and File Servers
  • BitDefender® Small Business Security for Desktops, File Servers, and Exchange

News

  • BitDefender Total Security 2010 Receives Top Score from PC Security Labs Total Protection Test
  • BitDefender Finds IT Security Employees Likely to Disclose Sensitive Information on Social Networks
  • BitDefender Internet Security 2010 Receives Esteemed AV-Test Certification

Tools & Resources

  • Free Online Virus Scanner
  • Renew Product Licence
  • Download Trial Versions
  • Download Datasheets