|
|
As McAfee Labs predicted in a previous blog post regarding the Microsoft Windows Shell .LNK vulnerability, it was just a matter of time before malware started using Exploit-CVE2010-2568 to take advantage of this new Microsoft zero-day flaw. The flaw is described in CVE-2010-2568.
First, there was talk about PWS-Zbot (a.k.a. Zeus) using the vulnerability in encrypted emails that contained the malicious .LNK file(s); then our research team found a new variant of Downloader-CJX that extended its previous .LNK propagation strategy using social engineering with the new Exploit-CVE2010-2568 .LNK files.
Downloader-CJX is a malware family that installs .LNK files mimicking current Windows and user folders such as Music, Documents, or New Folder. The malware changes the attributes of the real folder to hide it from Explorer, and drops the .LNK files with folder icons, so the user is lured into clicking on these malicious links that appear as legitimate folders. These .LNK files are detected as Downloader-CJX!lnk when found in an infected machine.
The new variant drops additional files on infected systems:

The file x.exe is another copy of Downloader-CJX that in turn drops xxx.dll, a DLL component of Downloader-CJX.
The additional .LNK files exploit the CVE-2010-2568 vulnerability, enabling the malware to load the DLL file when users browse the folder.
These .LNK files are already detected as Exploit-CVE-2010-2568 and the new Downloader-CJX variant as Downloader-CJX.gen.g.
We offer you yet another reminder to keep your anti-malware software updated with the latest DATs, because the bad guys are always updating their software, too.
|
|
Good Day,
I’m also experiencing this problem and the latest dat files at not helping at all in the prevention of this virus. A speedy solution to this problem is badly needed as this is a very annoying virus
netlab
McAfee Stinger version 10.1.0.1056 Build on 24 september 2010.
Volgende foutmelding:
Standalone anti-virus scanner for certain viruses, is een fout opgetreden en moet worden afgesloten. Onze excuses voor het ongemak.
U was bezig met een bewerking. Deze gegevens zijn mogelijk verloren gegaan.
Fout opsporen Sluite
This explains what the virus is…but not way to resolve it!? Come on guys!
Submit your own comments / message for this post