F-Secure: Be Sure
Main
F-Secure Logo - Be Sure
Select local site


Privacy Policy
Contact Us

F-Secure Virus Information Pages : PFV-Exploit.D

[Summary] | [Detailed Description]

Name:PFV-Exploit.D
Alias:Exploit.Win32.IMG-WMF
Size:53608
Category:Virus
Platform:Win32

Summary

PFV-Exploit.D was spammed on January the 1st 2006 with subject "Happy New Year" and body text "picture of 2006". The email contains an attachement file "HappyNewYear.jpg" which exploits the Microsoft WMF SetAbortProc vulnerability.

Detailed Description

When the infected attachement is viewed on vulnerable computer, it tries to download and execute a file from web server www.ritztours.com. The file is a variant of Bifrose backdoor, detected as W32/Bifrose.KT.

Please see the following links for more details about the WMF vulnerability:

http://www.kb.cert.org/vuls/id/181038
http://www.microsoft.com/technet/security/advisory/912840.mspx
http://www.f-secure.com/weblog/


Back to the Top


Write-up: Jarkko Turkulainen

Technical Details: Jarkko Turkulainen, January 1, 2006

F-Secure Corporation