
In November 2009, the distribution of malicious programs under the guise of programs that were allegedly able to track the location of the owners of cell phones was activated. Information about this is given in the November report on viruses and malicious software of Doctor Web .
Earlier, attackers who operated the "mobile" topic for the implementation of their schemes did not use harmful programs. However, in November, several Russian -speaking mailings took place on the topic of software designed to track mobile phones users. The aim of these mailings was the distribution of malicious programs designed to abduct user passwords.
In the early days of November, a postal message was sent, which supposedly contained software that allows you to detect the exact location of the owner of any mobile phone. At the same time, potential victims were interested in a proposal to try the possibilities of the program for free. In fact, the attached executable file was a program - Trojan.pws.acchunt.11 password kidnapper.
Another similar program, Trojan.pws.multi.109, spread under the guise of the same “useful” software as the previous one, but this time it was called a “diaper”. In the archive attached to the letter there were 2 files, one of which was a completely legal installer, and the other - a specially prepared installation package.
As one of the main channels of the distribution of Trojan programs in November, various types of messages on social networks were still used, and the flow of viruses spreading in the form of postal messages underwent a local decline by the end of November.
In November, the distribution of representatives of families of harmful programs that had previously walked on the Internet continued. In November, new modifications of Trojan.pws.panda passwords and Trojan Trojan.proxy family were recorded.
{pic_1 c}
However, since antivirus companies constantly inform users about malicious mailings made by attackers, sooner or later virus -writers have to take care of the issue of "change of scenery".
In addition, one of the main events of November 2009 was the new modification of Rutkin Backdoor.tdss, which uses various hiding technologies in the system, providing attackers with complete control over the infected computer.