Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Trojan-Downloader:W32/Valenavir.A


Aliases:


Trojan-Downloader:W32/Valenavir.A

Malware
Trojan-Downloader
W32

Summary

Valenavir.A disguises itself as a Valentine's eCard notification. When you click on the link in the notification e-mail, it will redirect you to a page that attempts to persuade users into installing additional malware.



Disinfection & Removal

Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.



Technical Details

Trojan-Downloader:W32/Valenavir.A disguises itself as a Saint Valentine's Day eCard notification.The eCard notification arrives in spammed e-mail. When you click on the link in the e-mail, it will redirect you to a page that asks you to install a fraudulent Adobe Flash Player. The software is supposedly required in order to view the eCard. This fraudulent application is actually a Trojan-Spy that downloads and installs a Trojan-Spy:W32/BZub variant onto the system.Once installed, Valenavir.A connects to:

  • http://www.nownames.org/new/[blocked].php?l=Un

Which redirects to:

  • http://dedmazay.3322.org/images/[blocked].exe.

The attempted download is detected as Trojan-Spy:W32/Bzub.HZ.







Submit a sample




Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Give And Get Advice




Give advice. Get advice. Share the knowledge on our free discussion forum.

Scan and clean your PC




F-Secure Online Scanner will scan and clean your PC in just a few minutes for free