Friday 19 April 2013

Microsoft have spotted a Trojan downloader executes files deletes itself

Microsoft malware protection center discovered a  malware  a trojan downloader, and is capable of deleting its downloaded component files in a way that makes them essentially unrecoverable.
The threat detected as TrojanDownloader:Win32/Nemim.gen!A.
Sometimes, when we don't have any evidence of what an individual downloads, we cannot be sure what the result of infection will be. Occasionally we can't replicate the downloader if the URLs are unavailable, so it can be difficult to know how to mitigate the threat. In the case of this downloader, however, we've observed it downloading a password stealer. As such, if you're infected with TrojanDownloader:Win32/Nemim.gen!A, we recommend you change all account passwords after you've cleaned your system, as it's likely you've also encountered PWS:Win32/Nemim.A.( read Microsoft Blog)
Below are the component files that Microsoft found that this malware downloads and executes, the ones that will eventually be deleted by the malware itself:
  • Virus:Win32/Nemim.gen!A – This is a file infector that attempts to infect executable files in removable drives. Infected files are detected, and subsequently cured, as Virus:Win32/Nemim.A. It appends its code to the Host file but it will not infect other files, rather it will only drop and execute the malware TrojanDownloader:Win32/Nemim.gen!A.
  • PWS:Win32/Nemim.A – This malware is a password stealer that attempts to steal account credentials from the following:
  • Email accounts (SMTP, POP3, HTTP mail, IMAP) that was setup in the system
  • Windows Messenger/Live Messenger
  • Gmail Notifier
  • Google Desktop
  • Google Talk

No comments:

Post a Comment