Autorun and JavaScript now main source of infection says BitDefender
Computer users’ growing demands for online interaction exposes them to all sorts of malicious software.
Currently the most common threats are to be found on file sharing websites such as torrent portals, “warez” communities and other services hosting pirated content.
Trojan.Clicker.CM ranks first in BitDefender’s top five e-threats for January. This Trojan is in fact a small script forcing advertisements inside the users’ browser. While some of the advertisements are related to free online games, others may expose the computer user to hardcore pornography or other types of inappropriate content.
In second place is Trojan.AutorunInf.Gen, a generic mechanism to spread malware using removable devices such as flash drives, memory cards or external hard-disk drives. Win32.Worm.Downadup and Worm.Zimuse are two of the most famous families of malware to use this approach to infect other systems.
Great attention should therefore be paid to the use of such external devices, warns Catalin Cosoi, BitDefender’s senior antispam researcher.
“Whilst they may be a convenient way to transfer data, memory sticks might easily harm the computer if used carelessly. Libraries, copy shops and other public hotspots are usually the most notorious sources of infection.”
Ranking third in this month’s e-threat report is Win32.Worm.Downadup.Gen. Exploiting the Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability (MS08-67), this worm spreads on other computers in the local network and restricts users’ access to Windows Update and security vendors’ web pages.
According to BitDefender, newer variants of the worm also install rogue antivirus applications, among others. The worm’s persistence after more than one year since its original appearance reveals that most users are reluctant to updating both the operating system and their locally-installed antimalware solution.
Exploit.PDF-JS.Gen comes in fourth place. This generic detection deals with malformed PDF files exploiting different vulnerabilities found in Adobe PDF Reader’s Javascript engine in order to execute malicious code on a user’s computer. Upon opening an infected PDF file, a specially crafted Javascript code triggers the download and automatic execution of malicious binaries from remote locations.
Ranking fifth is Trojan.Wimad.Gen.1. This Trojan is mostly found on torrent websites disguised as an episode of a popular television series that has not yet been aired. These fake video files are able to connect to a specific URL and download malware posing as the appropriate codec required for playing the file. Trojan.Wimad.Gen.1 is particularly active when box-office titles are expected to appear on file-sharing websites.
BitDefender's January 2010 top ten e-threat list includes:
1 Trojan.Clicker.CM 8.30
2 Trojan.AutorunINF.Gen 8.17
3 Win32.Worm.Downadup.Gen 6.18
4 Exploit.PDF-JS.Gen 5.76
5 Trojan.Wimad.Gen.1 4.30
6 Win32.Sality.OG 2.73
7 Trojan.Autorun.AET 2.01
8 Worm.Autorun.VHG 1.69
9 Trojan.Script.254568 1.40
10 Trojan.JS.QAF 1.40
OTHERS 58.01
BitDefender will be participating at Infosecurity Europe 2010, the No. 1 industry event in Europe held on 27th - 29th April in its new venue Earl's Court, London. The event provides an unrivalled free education programme, exhibitors showcasing new and emerging technologies and offering practical and professional expertise. For further information please visit www.infosec.co.uk
About BitDefender®
BitDefender is the creator of one of the industry's fastest and most effective lines of internationally certified security software. Since its inception in 2001, BitDefender has continued to raise the bar and set new standards in proactive threat prevention. Every day, BitDefender protects tens of millions of home and corporate users across the globe - giving them the peace of mind of knowing that their digital experiences will be secure. BitDefender solutions are distributed by a global network of value-added distribution and reseller partners in more than 100 countries worldwide. More information about BitDefender and its products are available at the company’s security solutions press room. Additionally, BitDefender’s www.malwarecity.com provides background and the latest updates on security threats helping users stay informed in the everyday battle against malware.

