Threat Description

Trojan-Downloader:​W32/Valenavir.A

Details

Aliases: Trojan-Downloader:​W32/Valenavir.A
Category: Malware
Type: Trojan-Downloader
Platform: W32

Summary



Valenavir.A disguises itself as a Valentine's eCard notification. When you click on the link in the notification e-mail, it will redirect you to a page that attempts to persuade users into installing additional malware.



Removal



Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.



Technical Details



Trojan-Downloader:W32/Valenavir.A disguises itself as a Saint Valentine's Day eCard notification.The eCard notification arrives in spammed e-mail. When you click on the link in the e-mail, it will redirect you to a page that asks you to install a fraudulent Adobe Flash Player. The software is supposedly required in order to view the eCard. This fraudulent application is actually a Trojan-Spy that downloads and installs a Trojan-Spy:W32/BZub variant onto the system.Once installed, Valenavir.A connects to:

  • http://www.nownames.org/new/[blocked].php?l=Un

Which redirects to:

  • http://dedmazay.3322.org/images/[blocked].exe.

The attempted download is detected as Trojan-Spy:W32/Bzub.HZ.






SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Scan & clean your PC

F-Secure Online Scanner will scan and clean your PC in just a few minutes for free

Learn More