- Recommend:
- 0 Comments
'Offensive' Trojan Can Disable PCs
However, worm hampers its own travels by damaging systems so thoroughly.
A new Trojan horse program that can severely limit user access to infected systems is spreading slowly worldwide, antivirus companies say.
The program, which is a script called either Trojan.JS.Offensive or Trojan.Offensive, can make Windows desktop icons invisible and can prevent users from starting programs or shutting down Windows. It even persists when a PC is being used in safe mode, according to information from antivirus vendor Symantec.
Luckily for users, the worm is not yet widespread and isn't likely to be, say antivirus vendors. Unlike a typical worm, which will often use an e-mail application to resend itself to other potential victims, Trojan.Offensive isn't likely to be able to spread itself because it locks up systems so extensively, says Craig Schmugar, a virus researcher with McAfee's AVERT Labs.
Trojan.Offensive arrives in users' e-mail in-boxes as an HTML e-mail message. However, it could also be available as Web page found on the Internet, if someone posted it there, Symantec says. The Trojan, written in Javascript, presents a "Start" button that, when clicked, activates the script. A variant of the Trojan lacks the "Start" button and activates when the file is opened. When executed, the Trojan makes a series of system-level changes to the configuration of the infected PC, greatly limiting user access to the system.
Drastic Remedies
The Trojan exploits a 10-month-old security hole in Microsoft's Java Virtual Machine, says McAfee's Schmugar. Systems that have applied Microsoft's patch are not vulnerable, he said.
The combination of an attack tool, called an exploit, and a Trojan is likely to become more common, as will the combination of exploits and worms, of which Code Red was an example, Schmugar says.
"I suspect we will see a lot more use of vulnerabilities" in worms, viruses, and Trojans, he says. In fact, a Web site exploiting this same vulnerability and using the same technique, but not using Trojan.Offensive itself, was discovered by AVERT last week, he said. The site has since been taken offline, he says.
If a PC is infected by Trojan.Offensive, typical users should contact technical support staff immediately, Symantec says. Reinstalling Windows, deleting the Trojan using DOS, or changing the system settings back by hand are ways to remove the infection, Symantec says.
"The average end user is going to have a heck of a time getting around these problems," AVERT's Schmugar agrees.
Would you recommend this story? YES NO
- Recommend:
- 0 Comments
-
Speed Up Everything!
PCWorld shows you the secrets to improve performance on all your hardware.
-
Stellar Tech Deals
Don't miss out on great deals from around the web.
-
ThinkPad Edge E420 Lenovo Style in an Affordable Package
Buy now direct from Lenovo -
ThinkPad X220 Fast and light, with great input ergonomics and battery life, this powerhouse ultraportable is best-of-breed.
Buy now direct from Lenovo -
ThinkPad X120e One of the best netbooks ever, X120e has the best netbook keyboard ever--nothing else comes close
Buy now direct from Lenovo
- 12 Criteria for Selecting the Best ERP System Replacement An ERP system is your information backbone and reaches into all areas of your business and value chain. Replacing it can open unlimited business opportunities. This white paper explains the 12 criteria that allow you to identify and select the solution that will meet these expectations.
- Leveraging Social Computing Technologies for ERP Applications This white paper details how Web 2.0 technologies support business strategies by improving efficiency, productivity, and collaboration.






















