Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Exploit:W32/AdobeReader.UZ


Aliases:


Exploit.PDF-JS.Gen
Exploit.JS.Pdfka.atq

Malware
Exploit
W32

Summary

A program or technique that takes advantage of a vulnerability to remotely access or attack a program, computer or server.



Disinfection & Removal

Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.



Technical Details

The detection Exploit:W32/AdobeReader.UZ identifies a malicious PDF document that attempts to exploit a known vulnerability in order to drop and run a malicious executable file on the system.

The exploit-code will not drop the executable if any of the following folders exist on the system:

  • C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009
  • C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009
  • C:\Program Files\Kingsoft

The vulnerability targeted lies in the Doc.media.newPlayer Javascript method (CVE-2009-4324).


Execution

The executable file embedded in the PDF will be dropped to:

  • %temp%\AdobeUpdate.exe

The dropped file will then be executed and will attempt to download additional files on to the system.

We detect the drooped file as Trojan-Downloader:W32/Agent.MRL.







Submit a sample




Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Give And Get Advice




Give advice. Get advice. Share the knowledge on our free discussion forum.