Content

Exploit-PDF.q.gen

Type
Trojan
SubType
Generic
Discovery Date
05/30/2009
Length
Minimum DAT
5635 (06/03/2009)
Updated DAT
5743 (09/16/2009)
Minimum Engine
5.2.00
Description Added
05/30/2009
Description Modified
06/04/2009 9:54 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

Exploit-PDF.q.gen is not intented to be vulnerabity-specific. It is a generic detection for malformed PDF files containing malicious Javascript.

Symptoms

Symptoms of malware vary greatly depending on the content of the malicious Javascript.  Some common symptoms which may be observed are as follows:

  • Download of other malware
  • Dropping an embedded executable file

 

Method of Infection

The malicious PDF file may be sent via e-mail or downloaded from a remote site.

Removal

All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

Exploit-PDF.q.gen is a generic detection for malformed PDF files containing malicious Javascript.

Characteristics

Characteristics -

Exploit-PDF.q.gen is not intented to be vulnerabity-specific. It is a generic detection for malformed PDF files containing malicious Javascript.

Symptoms

Symptoms -

Symptoms of malware vary greatly depending on the content of the malicious Javascript.  Some common symptoms which may be observed are as follows:

  • Download of other malware
  • Dropping an embedded executable file

 

Method of Infection

Method of Infection -

The malicious PDF file may be sent via e-mail or downloaded from a remote site.

Removal -

Removal -

All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A