View Single Post
Old 09-10-2002, 07:55 AM  
jimmyf
OU812
 
Join Date: Feb 2001
Location: California
Posts: 12,651
Trojan horse a real nice one

1. The Graphic Trojan
Kaspersky Labs reports the detection of a Trojan horse, FireAnvil,
embedded in a commercial product from US company,
Firehand Technologies Corporation.

"Firehand Ember Millennium" is a software program for viewing and
editing graphic files and is sold via Internet on the site
www.firehand.com. Trojan subprograms have been detected in two files of
the product: Ember32.exe - the main file of the product fireutil.dll -
library

The program is activated when the text "czy czy" is entered in the field
"Registered User ID".
Registered User ID: [_________]
Registration Key: [_________]

As the Trojan program is activated the following message is displayed:

CrAcKiNg SoFtWaRe! PlEaSe WaIt!

Then FireAnvil searches for the Windows system directory and writes the following text into the registry of all of the files within the directory:

CzY CrAcKiNg CrUe! We CrACk EvErYtHiNg!

As a result of the program's destructive function, when activated, all of the files of the Windows system directory are destroyed with no possibility of restoring them.
__________________
Epic CashEpic Cash works for me
Solar Cash Paysite Plugin
Gallery of the day freesites,POTD,Gallery generator with free hosting
jimmyf is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote