Classification

Category :

Malware

Type :

-

Aliases :

Apher, TrojanDownloader.Win32.Apher.gen, Backdoor.Death.25.gen

Summary

A new trojan Apher has been found on August 20th, 2002.

Removal

Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.

A False Positive is when a file is incorrectly detected as harmful, usually because its code or behavior resembles known harmful programs. A False Positive will usually be fixed in a subsequent database update without any action needed on your part. If you wish, you may also:

  • Check for the latest database updates

    First check if your F-Secure security program is using the latest updates, then try scanning the file again.

  • Submit a sample

    After checking, if you still believe the file is incorrectly detected, you can submit a sample of it for re-analysis.

    Note: If the file was moved to quarantine, you need to collect the file from quarantine before you can submit it.

  • Exclude a file from further scanning

    If you are certain that the file is safe and want to continue using it, you can exclude it from further scanning by the F-Secure security product.

    Note: You need administrative rights to change the settings.

Technical Details

It was distributed in email messages as follows:

From:[info@microsoft.com]
Subject:Protect Your NetWare with




KasperskyTM Anti-Virus
Body:
"Kaspersky Labs, an international data-security software
developer, announces the official release of Kaspersky
Anti-Virus
4.0. "We are pleased to present the latest
version of our anti-virus product. The unique technology,
updated design, and perfected administering system integrated
into Kaspersky Anti-Virus 4.0 is the result of many years
of work dedicated to improving the ease of working with
the program and increasing computer defense reliability,"
said Natalya Kaspersky, Kaspersky Labs CEO. The new Kaspersky
Anti-Virus version (Personal Pro, Personal, Lite) fully
supports the Microsoft Windows XP operating system. Amongst
this versions latest innovations are: a complete user interface
upgrade corresponding to Tree Chart technology; perfected system
installation that allows for the saving the configuration of
previously installed versions, and a quarantine feature for
isolating infected and suspicious objects; expanded treatment of
infected archived files; an added function for the treatment of
Microsoft Outlook Express and objects upon system start up and
also a memory scanning of active applications; and simplified
operating features for disk recovery.
Best regards,
If you have any questions
please call
+1(866) 7280-290"
Attachment: AAPRICES.EXE

Once the attachment is executed it downloads and silently executes from a Russian web site a file Slnew.exe. This file is new variant of Backdoor.Death.25. The backdoor provides access to the compromised computer for a remote attacker.