Content
W32/Yourde
- Type
- Virus
- SubType
- File Infector
- Discovery Date
- 04/24/2003
- Length
- Varies
- Minimum DAT
- 4260 (04/30/2003)
- Updated DAT
- 4260 (04/30/2003)
- Minimum Engine
- 5.1.00
- Description Added
- 04/26/2003
- Description Modified
- 04/30/2003 12:10 PM (PT)
Tab Navigation
Characteristics
This virus infects PDF documents when using the full version of Adobe Acrobat (version 5.x) for Windows. It does not affect the Acrobat Reader. The virus simply spreads from one document to another and does not cause any system damage. It exploits a vulnerability in Acrobat. For more information on this vulnerability and a patch, see: Adobe Acrobat 5.0.5 Security, Accessibility, and Forms patch - English
The virus works by exporting virus code to your hard disk and configuring Acrobat to import this virus code into each .PDF document that is opened in Acrobat. When a document is saved on the infected system, it becomes a carrier for this virus. The methods used by the virus do not work on the Macintosh systems, however they can be a carrier of the virus when receiving an infected document.
When an infected .PDF file is opened with the full version of Acrobat, javascript within the document is executed. This javascript exports two embedded data objects to the file system:
- C:\EVIL.FDF
- %Adobe Plugins Folder%\death.api
The virus contains the string Your_Death
Symptoms
Presence of the following files:
- C:\EVIL.FDF
- %Adobe Plugins Folder%\death.api
Method of Infection
Infection summary (similar to a macro virus):
- Infected file is opened
- Virus is exported to hard disk
- Virus is run
- Virus is imported in to "clean" document
- Document is saved and now a carrier
Removal
The detection and removal of this malware requires an extra.dat, which is available upon request.
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Characteristics
Characteristics -
This virus infects PDF documents when using the full version of Adobe Acrobat (version 5.x) for Windows. It does not affect the Acrobat Reader. The virus simply spreads from one document to another and does not cause any system damage. It exploits a vulnerability in Acrobat. For more information on this vulnerability and a patch, see: Adobe Acrobat 5.0.5 Security, Accessibility, and Forms patch - English
The virus works by exporting virus code to your hard disk and configuring Acrobat to import this virus code into each .PDF document that is opened in Acrobat. When a document is saved on the infected system, it becomes a carrier for this virus. The methods used by the virus do not work on the Macintosh systems, however they can be a carrier of the virus when receiving an infected document.
When an infected .PDF file is opened with the full version of Acrobat, javascript within the document is executed. This javascript exports two embedded data objects to the file system:
- C:\EVIL.FDF
- %Adobe Plugins Folder%\death.api
The virus contains the string Your_Death
Symptoms
Symptoms -
Presence of the following files:
- C:\EVIL.FDF
- %Adobe Plugins Folder%\death.api
Method of Infection
Method of Infection -
Infection summary (similar to a macro virus):
- Infected file is opened
- Virus is exported to hard disk
- Virus is run
- Virus is imported in to "clean" document
- Document is saved and now a carrier
Removal -
Removal -
The detection and removal of this malware requires an extra.dat, which is available upon request.
Variants
Variants -
N/A