Trojan infects 10,000 Australian PCs (1 Viewer)

mr_brightside

frakfrakfrakcackmackshack
Joined
Jan 29, 2005
Messages
1,678
Location
Sydney
Gender
Male
HSC
2005
By Simon Lauder for The World Today

A trojan known as A311 Death is estimated to have infected 10,000 computers in Australia.

The Australian Computer Emergency Response Team is investigating the program, which is believed to have come from Russia.

Chris Horsley, a AusCERT security analyst, says thousands of Australian PCs are infected, and the trojan is spreading fast.

"Our current estimate is around 10,000 but there's more infections worldwide," he said.

"They seem to be constantly feeding new runs of this particular trojan by a lot of different vectors."

The Australian Tax Office says the A311 Death trojan has been used to detect the tax file numbers of 200 people who have lodged their tax returns online.

Those people have all been offered new tax file numbers, and a spokeswoman says lodging a tax return online is still considered safe if users have the latest virus detection software.


But Mr Horsley says most anti-virus programs will not detect the trojan.

"Sometimes not. One of the methods that the trojan uses is disabling antivirus and also changing the operating system to hide its presence from the programs running on it," he said.

"So that's made detection in this particular case quite difficult."

But Peter Cassidy, from the US based Anti-Phishing Working Group, says virus protection is still a good idea.

"It offers probably as much protection as a seatbelt will," he said.

"None of it's perfect but you would never want to drive without wearing a seat belt.

"Antivirus is the same way. You'd rather have it than not."
Phishing

The trojan is the latest example of online phishing.

As the proceeds from electronic crime continue to grow - they topped $100 billion in 2004 - scammers are outsourcing phishing work to programmers to seize control of home computers.

"Program writers and people who control bot networks, basically aggregations of machines, that are controlled by a third party that's not paying for the service," Mr Cassidy said.

"They commandeer the machine and they then rent out their services to people who want to drive phishing attacks."

Mr Cassidy says a new type of technical subterfuge is emerging - programs that can retrieve data from a computer with no participation from the user.

"What we see happening is complete automation of phishing, and the submergence of phishing below detectable levels," he said.

"Phishing now, most of it, we can actually see.

"But, what we're seeing is a trend over time, over the years, is that crimeware as it develops, becomes very, very difficult to detect.

"And that future is already here in places like Brazil."

A311 Death is not quite as sophisticated as that but Mr Horsley, says it still has the ability to get as much data as the user puts into their computer.

"Generally, what they're looking for are ... every time you connect to a website, and you transmit data to that website, they're saving a copy of that data off," he said.

"That would include things like when you're connecting to webmail sites, when you're connecting to any sites involving credentials.

"Those are the main things they're after."
:S

Zone Alarm detected a trojan sometime last week on my PC and deleted it, and im guessing this was it. Anyone know how it is transmitted or anything about it?

The bit in bold is particulary worrying,
so I thought I would post to make other people aware.
 

sam04u

Comrades, Comrades!
Joined
Sep 13, 2003
Messages
2,867
Gender
Male
HSC
2006
mr_brightside said:
:S

Zone Alarm detected a trojan sometime last week on my PC and deleted it, and im guessing this was it. Anyone know how it is transmitted or anything about it?

The bit in bold is particulary worrying,
so I thought I would post to make other people aware.
Dude, That's a stupid MSN Buddy List, trojan. You've probably seen it's adds by the stupid people on your buddy list. "To Check Out other people emails go to this website and download email-blocker, to see who blocked you!"

The idiots who clicked on it got infected, and left it on their computers. It's not even that powerful, and old version of ad-aware could pick it up. I'm guessing that number is far less the the actual numbers of people infected (I'd say close to 100,000) [I'm sure that was the trojans name, I always thought it was korean though... why would they say russian?]
 

mr_brightside

frakfrakfrakcackmackshack
Joined
Jan 29, 2005
Messages
1,678
Location
Sydney
Gender
Male
HSC
2005
sam04u said:
Dude, That's a stupid MSN Buddy List, trojan. You've probably seen it's adds by the stupid people on your buddy list. "To Check Out other people emails go to this website and download email-blocker, to see who blocked you!"

The idiots who clicked on it got infected, and left it on their computers. It's not even that powerful, and old version of ad-aware could pick it up. I'm guessing that number is far less the the actual numbers of people infected (I'd say close to 100,000) [I'm sure that was the trojans name, I always thought it was korean though... why would they say russian?]
=\

No its not. Thats old....way old
and im not stupid enough to get duped into that anyway.
 

cjwrighty

Look out UOW here I come!
Joined
May 2, 2005
Messages
19
Location
Wollongong, NSW
Gender
Male
HSC
2006
its weird that in that release posted by mr_brightside, (if it is a offical release) didnt have any information on how the trojan is spreading and any information about how it shows on the computer, like a common file name it uses and other information like that. Also i am surprised that it is only detected on some Anti Virus programs, you would think that the makers of the programs would get there ass into gear to make an update for the programs so that they can detect this trojan and hope that it doesnt get any other people private information.
 

Optophobia

Member
Joined
Feb 1, 2006
Messages
696
Gender
Male
HSC
2005
Yeh, and they are trying to make it sound like its the computer equivalent of SARS (No known cure!! spreading fast!!), which is sort of difficult on computers.
 

gtvwill

Member
Joined
Sep 11, 2005
Messages
36
Gender
Male
HSC
2006
Lol pwnt, remember kids get a good AV a good Firewall a adware scanner, malwhere and a good process/task manager program and your set :D

What setup do you all use? i use ZA pro for firewall, Kaspersky personal pro AV, Adware as adware scanner (even tho both ZA and Kaspersky scan for adware) along with MalWhere to check running processes.

Also if any of you come across a rootkit.trojan.l virus...ur fux0red :) so as soon as u detect it start backin yo shit up.
 

AppleXY

s00 l33t xD
Joined
Apr 29, 2006
Messages
969
Location
World
Gender
Male
HSC
2008
Uni Grad
2019
wen i'm doing anything with secure, i use my mac :)
 

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

Top