Content

QDel378

Type
Trojan
SubType
Trojan
Discovery Date
04/09/2003
Length
73 Bytes
Minimum DAT
4258 (04/16/2003)
Updated DAT
4406 (11/10/2004)
Minimum Engine
5.1.00
Description Added
04/09/2003
Description Modified
04/09/2003 7:48 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This trojan when executed will perform the following:

  • Hides all commands from appearing on the on the screen
  • Blocks the user from sending a command. To halt the batch from executing
  • Overwrites the "autoexec.bat" with a file named "fotos.bat"
  • Deletes all folders from the root of the C drive

Symptoms

Presence of a file called "fotos.bat" on the system

Method of Infection

This is a trojan and therefore does not self propagate. Trojans are typically spread by users distributing them via Internet Relay Chat, newsgroup and message board postings, and email.

Removal

All Users :
Use specified engine and DAT files for detection and removal. Delete files which contain this detection.

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

This is a trojan detection. Unlike viruses, trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.

Characteristics

Characteristics -

This trojan when executed will perform the following:

  • Hides all commands from appearing on the on the screen
  • Blocks the user from sending a command. To halt the batch from executing
  • Overwrites the "autoexec.bat" with a file named "fotos.bat"
  • Deletes all folders from the root of the C drive

Symptoms

Symptoms -

Presence of a file called "fotos.bat" on the system

Method of Infection

Method of Infection -

This is a trojan and therefore does not self propagate. Trojans are typically spread by users distributing them via Internet Relay Chat, newsgroup and message board postings, and email.

Removal -

Removal -

All Users :
Use specified engine and DAT files for detection and removal. Delete files which contain this detection.

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A