|
RuSpy.A is a Trojan that obtains user names and passwords for a range of programs including ICQ, Internet Explorer, Mozilla, Outlook and The Bat!. This information is then sent to the creator in an email message. To avoid detection, it tries to terminate several processes belonging
to security tools (antivirus programs and files). As well as sending
out the information mentioned before, it tries to download the file
XINCH.EXE from a web page and creates shortcuts to several websites
(all with Russian "ru" domains), and alters the Internet
home page on the infected system. Tervserv.A can also be instructed to send information about files
on the computer as well as update or uninstall itself. When an infected user opens one of these pages, Banker.DZO displays a false login page in order to obtain the user name and password for accessing accounts. This information is then sent to the creator in an email message. The information compiled is quite extensive, ranging from the particular bank or branch of the user to the password or even the secret password reminder question.
|