Additional Details
The Needy.E is activated when a web site containing the
trojan is loaded with unpacthed Microsoft Internet Explorer
browser. When the JAR file containing the trojan is executed
it uses Microsoft Internet Explorer VerifierBug vulnerability to get
full privileges by escaping the Java security, and execute its
code.
When executed the trojan modifies the Internet Explorer start page
to point to the site where the trojan is downloaded from, and changes
search settings to point to pornographic services.
In addition to changing the Internet Explorer settings the trojan
downloads trojan downloader win32.barlf and executes it.
Detection
Detection in F-Secure Anti-Virus was published on March 30th, 2004 in
update:
[FSAV_Database_Version]
Version=2004-03-30_02
Write-up:
Jarno Niemela, March 30th, 2004;