October 23, 2006 4:44 PM PDT

Trojan horse installs antivirus program

by Joris Evers
  • Font size
  • Print
  • Post a comment

In addition to setting up a compromised computer to relay spam, one example of malicious software also installs Kaspersky Lab's antivirus program to get rid of competing malicious software.

The culprit is a Trojan horse sometimes called "SpamThru," according to a write-up by Joe Stewart, a researcher with SecureWorks. "SpamThru is a money-making operation, and the author takes great care to make sure that detection by the major vendors is avoided by frequently updating the code," Stewart wrote last week.

When it first gets onto a PC, SpamThru connects to a control server and subsequently installs a pirated copy of Kaspersky AntiVirus, Stewart wrote. The system then starts a scan for malicious software, skipping files that it detects are part of its own installation, he wrote.

"SpamThru takes the game to a new level, actually using an antivirus engine against potential rivals," Stewart wrote. "Any other malware found on the system is then set up to be deleted by Windows at the next reboot."

Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
advertisement
Click Here

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement
Click Here

Inside CNET News

Scroll Left Scroll Right