Watch for this trojan VBS/Psyme
http://vil.nai.com/vil/content/v_100749.htm
This trojan exploits an unpatched (at the time of this writing) vulnerability in Internet Explorer. The vulnerability allows for the writing, and overwriting, of local files by exploiting the ADODB.Stream object. There are several variants of this trojan. Therefore this description is design to give an overview of how the trojan works.
The trojan exists as VBScript. This script contains instructions to download a remote executable, save it to a specified location on the local disk, and then execute it.
Restore for98/me
Friday, March 19, 2004
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment
I welcome feedback or comments on my blog, but please, no advertisements.