Threat Description

Apher

Details

Aliases: Apher, TrojanDownloader.Win32.Apher.gen, Backdoor.Death.25.gen
Category: Malware
Type:
Platform: W32

Summary


A new trojan Apher has been found on August 20th, 2002.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

Detailed instructions for F-Secure security products are available in the documentation found in the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for further assistance.



Technical Details


It was distributed in email messages as follows:

From:[info@microsoft.com]  Subject:Protect Your NetWare with          KasperskyTM Anti-Virus  Body:  "Kaspersky Labs, an international data-security software  developer, announces the official release of Kaspersky  Anti-Virus  4.0. "We are pleased to present the latest  version of our anti-virus product. The unique technology,  updated design, and perfected administering system integrated  into Kaspersky Anti-Virus 4.0 is the result of many years  of work dedicated to improving the ease of working with  the program and increasing computer defense reliability,"  said Natalya Kaspersky, Kaspersky Labs CEO. The new Kaspersky  Anti-Virus version (Personal Pro, Personal, Lite) fully  supports the Microsoft Windows XP operating system. Amongst  this versions latest innovations are: a complete user interface  upgrade corresponding to Tree Chart technology; perfected system  installation that allows for the saving the configuration of  previously installed versions, and a quarantine feature for  isolating infected and suspicious objects; expanded treatment of  infected archived files; an added function for the treatment of  Microsoft Outlook Express and objects upon system start up and  also a memory scanning of active applications; and simplified  operating features for disk recovery.  Best regards,  If you have any questions  please call  +1(866) 7280-290"  Attachment: AAPRICES.EXE  

Once the attachment is executed it downloads and silently executes from a Russian web site a file Slnew.exe. This file is new variant of Backdoor.Death.25. The backdoor provides access to the compromised computer for a remote attacker.



Detection


F-Secure Anti-Virus detects Apher Death.25 with the update published on August 20th, 2002:

Detection Type: PC
Database: 2002-08-20_01



Description Details: Analysis: Katrin Tocheva, Gergely Erdelyi and Ero Carrera; F-Secure Corp.; August 20th, 2002


SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More