Threat description



A new trojan Apher has been found on August 20th, 2002.


Automatic action

Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.

Technical Details

It was distributed in email messages as follows:

Subject:Protect Your NetWare with

KasperskyTM Anti-Virus
"Kaspersky Labs, an international data-security software
developer, announces the official release of Kaspersky
4.0. "We are pleased to present the latest
version of our anti-virus product. The unique technology,
updated design, and perfected administering system integrated
into Kaspersky Anti-Virus 4.0 is the result of many years
of work dedicated to improving the ease of working with
the program and increasing computer defense reliability,"
said Natalya Kaspersky, Kaspersky Labs CEO. The new Kaspersky
Anti-Virus version (Personal Pro, Personal, Lite) fully
supports the Microsoft Windows XP operating system. Amongst
this versions latest innovations are: a complete user interface
upgrade corresponding to Tree Chart technology; perfected system
installation that allows for the saving the configuration of
previously installed versions, and a quarantine feature for
isolating infected and suspicious objects; expanded treatment of
infected archived files; an added function for the treatment of
Microsoft Outlook Express and objects upon system start up and
also a memory scanning of active applications; and simplified
operating features for disk recovery.
Best regards,
If you have any questions
please call
+1(866) 7280-290"
Attachment: AAPRICES.EXE

Once the attachment is executed it downloads and silently executes from a Russian web site a file Slnew.exe. This file is new variant of Backdoor.Death.25. The backdoor provides access to the compromised computer for a remote attacker.


F-Secure Anti-Virus detects Apher Death.25 with the update published on August 20th, 2002:

Detection Type: PC

Database: 2002-08-20_01

Submit a Sample

Suspect a file or URL was wrongly detected? Send it to our Labs for further analysis

Submit a Sample

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

More Info