Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 9th, 2003, 06:39 AM
Randy_Bell's Avatar
Randy_Bell Randy_Bell is offline
Updates Team
 
Join Date: May 2002
Location: Santa Clara, CA
Posts: 3,053
Default JS_WEBLOG.A

JS_WEBLOG.A is a JavaScript Trojan that retrieves all data entered in HTML Web forms on Internet Explorer. It then sends the retrieved data to a particular Web site or to a particular system on the same network. It affects systems running Internet Explorer on Windows 95, 98, ME, NT, 2000, and XP.

This JavaScript Trojan retrieves data entered in HTML forms on Internet Explorer and sends the data to a particular Web site or to a particular system on the same network. It does not have its own means of propagation and does not install itself. It is either installed manually or is dropped and installed by another malware.

This Trojan has two components. The first component retrieves any data entered in HTML forms that are accessed using the particular browser. It saves this gathered data in text files, which it generates under temporary names in the folder %Windows%TasksData

The text files contain the following information:

* Site/URL where the data is sent
* Date when the data is sent
* Values gathered from the HTML form/s

This malware's second component sends all of the data logged by the first component, to a particular Web site or system. It sends data in a continuous loop and reads all files in the directory where the log files are generated.

It uses HTTP to send the logged data to a particular Web site. If this fails, it drops a text file containing the logged data to a particular network share. To send the stolen data using HTTP, it formats the data in XML and then sends it to a specific URL. To connect to the share, it uses a specific account and then drops a text file containing the logged data into the share.

If you would like to scan your computer for JS_WEBLOG.A or thousands of other worms, viruses, Trojans and malicious code, visit HouseCall, Trend Micro's free, online virus scanner at: http://housecall.trendmicro.com/

JS_WEBLOG.A is detected and cleaned by Trend Micro pattern file #478 and above.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:33 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums