Troj_Yabe.R arrives as an attachment to email messages manually spammed by its author.
Upon execution, it connects to the Web site http://www.booBLOCKED}st.biz to download and execute a malicious file detected by Trend Micro as TSPY_BZUB.AC. Thus, an affected system becomes vulnerable to the malicious routines of the downloaded spyware.
Moreover, this Trojan attempts to bypass the Windows firewall so that it can freely execute its downloading routine. It also terminates certain antivirus-related processes if it finds them running on the affected system. The later action helps prevent its immediate detection and consequent removal.
Online Security Threats - Internet and Network Security Threats :: 7/5: Zachast.EH Backdoor Downloaded from URL - 07/05/2006 7/5: Yabe.R Trojan Arrives as Email Attachment - 07/05/2006 7/5: Audio Worm Spreads Over Floppy http://www.esecurityplanet.com/alerts/archives.php/200607HOME | Technical details can be found at this Trend Micro page.
Pre-Article:CSS Support is Poor in RSS Feed Readers Next-Article:Microsoft Office 2007 Preview: Worthy of an Upgrade? |