Trojans, top threat to Internet users

author-image
DQChannels Bureau
New Update

Romania: BitDefender released a lineup of the 10 most pernicious threats facing Internet users in the month of April. The top is still dominated by trojans, as it was in March, as these threats that rely solely on tricking the user for spreading occupy seven of the 10 positions. Only a couple of worms, exploits and viruses break up the 'trojan parade'.

Advertisment

Highlighting the importance of the web as the infection vector du jour, in 10th position the company found a 'silent' trojan that gets injected in vulnerable, legitimate websites. It is solely used to make visitors' browsers load exploit code, such as those detected by BitDefender as Exploit.SWF.Gen and Trojan.Exploit.ANPW in sixth and fifth place, respectively (this combination is found mainly on Chinese malicious websites).

Trojan.Peed.Gen (aka the venerable Storm Worm) racks up 1.81 percent of detections for April, but this time around, as a dropped component for some other threat-a sign, maybe, that while it's still useful, it has outlived its effectiveness as an infector and is now used only for the control functionality it provides to an attacker.

A newcomer occupies eigth spot-Trojan.KillAV.PT is a bit of 'utility' malware, which kills any antivirus or security process it can find (from a long list) on the target machine, prevents them from running ever again, then decrypts and executes a downloader, which in turn downloads and installs a game password stealer.

Advertisment

In seventh, Win32.Sality is the only true virus in the April top 10, a polymorphic file infector which modifies executable files (.exe and .scr) appending its encrypted body at the end of files in a newly created section.

Its other means of spreading is also a new old thing-linking to an infected executable from the Autorun.INF file found on removable media or network shares, a trick that has served the much newer Downadup aka. Conficker well.

The Conficker worm occupies fourth place, under the Win32.Worm.Downadup.Gen. Its capabilities are well-known by now, but the fact that it is still spreading vigorously enough to take up 3.05 percent of detections by itself is something of a surprise after all this time.

Advertisment

“We can only hope the high detection rate is due to the people who were previously infected finally running an anti-virus. However, I expect the reality is more along the lines of the worm being replicated by a sizeable network of infected machines,” Sorin Dudea, Head, BitDefender Antivirus Lab commented.

Two rather old adware trojans, Wimad and Clicker occupy the third and second spots.

Trojan.AutorunINF.Gen occupies first place. It is not a single e-threat, but rather a generic name for trojans which use the Autorun.INF spreading mechanism outlined above, but for which a specific signature has not been added.

Advertisment

“We're pretty pleased with having this kind of generic, no-human-in-the-loop detection work and work well. The future of reliable anti-virus detection depends on adapting to new e-threats in real-time and such techniques pave the way there,” Dudea said.