![]() |
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
![]() |

|
| Security News The Latest Computer Security News |
![]() |
|
PWS-Maran.dr
|
LinkBack | Thread Tools | Display Modes |
|
|
#1 (permalink) |
|
Administrator
Posts: 18,715
Join Date: Jan 2006
Rep Power: 10
IM:
|
Risk Assessment - Home Users: Low - Corporate Users: Low Date Discovered: 1/8/2007 Date Added: 1/8/2007 Origin: N/A Length: N/A Type: Trojan SubType: Dropper DAT Required: 4934 Virus Characteristics PWS-Maran.dr drops and registers an executable as a service and installs a dropped dll as a Layered Service Provider (LSP) to WinSock to sniff and steal personal information. On execution it drops the following files:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\NETDown
Indications of Infection
Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, email, etc. Removal Instructions AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination. Additional Windows ME/XP removal considerations Aliases Troj/Maran-Gen (Sophos), Trojan-PSW.Win32.Maran.ba (Kaspersky), TSPY_MARAN.D (Trend Micro) |
|
|
|
|
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
|
|