Skip to navigation
Latest News

Updated: Backdoor trojans make their presence felt

By Alun Williams

Posted on 12 Nov 2003 at 11:37

A virus never sleeps. And it seems they don't stop mutating and breeding, too, as there are two new threats to computer users: BDSinit-A and Webber-C.

Strictly speaking, they are back-door trojans rather than 'viruses', but they both allow a remote attacker to control your system. The anti-virus specialist Sophos has already received several reports from the wild for both the threats.

BDSinit-A works by copying itself into the Windows system folder as svcinit.exe and modifies the Registry for it to be executed on system start-up.

In terms of operation, it will open a random port on the PC in order to receive commands from a remote attacker.

Webber-C, believed to be of Eastern European (probably Polish) origin, is slightly more involved. Its loader component will download the cargo from a web address (www.valenok.red-host.com) into the Windows system folder, and then execute it, and its downloaded component is a password stealing trojan. This will attempt to extract sensitive information from several locations on the system - for example, files containing password info - and then send it to another part of the website.

The downloaded component is hard to detect because it will be stored using a random name. And the fact that the virus checks for orders from a website gives the attacker flexibility on what Webber-C will actually perform - it is not hard-coded into the trojan itself.

Sophos reports that Webber-C can also function as a web proxy, and it is believed it may be used to monitor users' web activity and retrieve information, possibly financial details, for example.

You can find more info on Troj/BDSinit-A and Troj/Webber-C on the Sophos Website.

Subscribe to PC Pro magazine. We'll give you 3 issues for £1 plus a free gift - click here

From around the web

Be the first to comment this article

You need to Login or Register to comment.

(optional)

advertisement

Most Commented News Stories
More From PC Pro
Latest Blog Posts Subscribe to our RSS Feeds
Latest ReviewsSubscribe to our RSS Feeds
Latest Real World Computing

advertisement

Sponsored Links
 
SEARCH
SIGN UP

Your email:

Your password:

remember me

advertisement


Hitwise Top 10 Website 2010
 
 

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.