Sophos

Troj/PDFex-E

Aliases
  • Exploit.Win32.Pidief.m
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 23 March 2008 20:38:14 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/PDFex-E is a Trojan for the Windows platform that exploits a vulnerability in Adobe Acrobat and Acrobat reader to drop malicious files.

When Troj/PDFex-E is run the following files are created:

- Flate0022 - detected as Mal/JSShell-A
- <Root>\a.exe - detected as Troj/PDFex-E
- <System>\sysqaz.exe - detected as Troj/PDFex-E

The file sysqaz.exe is a keylogger. It saves all the logged key strokes in file:

<System>\sysqaxz - plain text file, can be deleted.

The file sysqaxz is periodically uploaded to a remote site.

The following registry entry is created to run sysqaz.exe on startup:

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{0AD558D3-7440-AFB0-0506-030706020206}
StubPath
<System>\sysqaz.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer