Threat Description

Trojan-Downloader:​W32/Valenavir.A

Details

Aliases:Trojan-Downloader:​W32/Valenavir.A
Category:Malware
Type:Trojan-Downloader
Platform:W32

Summary



Valenavir.A disguises itself as a Valentine's eCard notification. When you click on the link in the notification e-mail, it will redirect you to a page that attempts to persuade users into installing additional malware.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.



Technical Details



Trojan-Downloader:W32/Valenavir.A disguises itself as a Saint Valentine's Day eCard notification.The eCard notification arrives in spammed e-mail. When you click on the link in the e-mail, it will redirect you to a page that asks you to install a fraudulent Adobe Flash Player. The software is supposedly required in order to view the eCard. This fraudulent application is actually a Trojan-Spy that downloads and installs aTrojan-Spy:W32/BZub variant onto the system.Once installed, Valenavir.A connects to:

  • http://www.nownames.org/new/[blocked].php?l=Un

Which redirects to:

  • http://dedmazay.3322.org/images/[blocked].exe.

The attempted download is detected as Trojan-Spy:W32/Bzub.HZ.






SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Scan & clean your PC

F-Secure Online Scanner will scan and clean your PC in just a few minutes for free

Learn More