Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Virus alerts

July 22nd, 2006, 10:04 GMT · By

Chinese Data Theft via PowerPoint Vulnerability Exploit

SHARE:

Adjust text size:


Symantec warns that a Zero-day exploit of PowerPoint vulnerability allows for the compromised computers to be used in data theft attacks. A malicious PowerPoint file infects the machine with Trojan.PPDropper.C that drops
additional malware in the form of Backdoor.Bifrose.E and Trojan.Riler.F. The two Backdoor Trojans allows remote access to a potentially compromised computer.

Backdoor.Bifrose.E is a keylogger that connects to pukumalon.8800.org a free host service on a China based server. All the data recorded by the keylogger is transmitted to the remote server.

"Trojan.Riler.F is a back door Trojan horse that installs itself as a layered service provider (LSP), and allows a remote attacker to have unauthorized access to the compromised computer. It is dropped by Trojan.PPDropper.C. When Trojan.Riler.F is executed, it creates the files: "%System%SNootern.dll" and "%System%uidmngr.ini", installs the file SNootern.dll as a layered service provider (LSP) and creates the following registry subkey: HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesWinSock2ParametersProtocol_Catalog9," describes Symantec.

Trojan.Riler.F also connects to soswxyz.8800.org, permitting access to al data stored or trafficked through the compromised computer. Microsoft has already announced that the PowerPoint vulnerability will not be patched until August 8.

TELL US WHAT YOU THINK:

2,208 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Microsoft Leaves PowerPoint Flaw Unfixed

PowerPoint Zero-day Attacks

Chinese Love Philosophy Exploits PowerPoint Flaw

Microsoft Patch Generates Problems

iAsk and Sogou - New Examples of Chinese Web Censorship?

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM