W32/Marlap.B Trojan
| Name |
W32/Marlap.B Trojan |
| Aliases |
PWSteal.Marlap.B |
| Discovered on |
March 27, 2006 |
Virus Information - W32/Marlap.B Trojan:
W32/Marlap.B is a trojan. The trojan will infect Windows systems.
Upon execution, the trojan copies itself as winServices.pif in Windows folder.
It also drops the following files.
[random].scr in Windows folder.
ejn[random].tmp in Windows temp folder.
The trojan modifies registry at the following location to load itself during each startup.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
It tries to connect to the following website and downloads a file.
http://[blocked].com/comcastdirect/1.exe
It displays a fake AOL form asking for the following personal information.
Name
Account Number
Account Type
Address
ZIP
Phone number
PIN number
Birthday
Mother's maiden name
Social Security Number
Credit Card number
It sends the entered information to php scripts in any one of the following websites.
http://johnste55.mapage.com
http://kjdfgjh56.saveinem2006.com
http://blajoe.freecoolsite.com
http://sj892.webgen.com
This trojans blocks access to some of the security related websites.

|