Home / malwarePDF  

Trojan-Downloader:JS/Agent.CKK


First posted on 05 September 2008.
Source: SecurityHome

Aliases :

There are no other names known for Trojan-Downloader:JS/Agent.CKK.

Explanation :

This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files.

right]Upon execution, this trojan tries to take advantage of the following vulnerability:

  • Microsoft Office Snapshot Viewer ActiveX vulnerability

If this vulnerability is present on the user's system, the malware exploits it in order to download and execute a file from the URL http://down.hs7yue.cn/[Removed]/ac.css. The downloaded file is detected as the malware Trojan.Win32.Agent.wnu.

The online F-Secure Health Check can help determine whether a user's system has vulnerabilities which can be exploited, and assist in finding fixes for any vulnerabilities discovered.

Last update 05 September 2008

 

TOP