|
 |
|
Beasty.C
|
|
|
Last Update:
|
2008-05-14 02:42
|
|
|
Risk Rating:
|

Very Low Risk
|
|
|
Aliases:
|
2000
Backdoor.Beastdoor.192
Backdoor.Beasty.C
In
ME
No
NT
Server
StartPage-FG
TR/Small.DBY.LH.12
Troj/Dloader-DG
Troj/Killav-I
TROJAN
Trojan.Win32.Agent.ass
Trojan.Win32.Killav.q
Trojan.Win32.StartPage.jc
TROJ_CRIMEA.A
TROJ_STARTPGE.R
W32/Crimea.dr
XP
|
|
|
|
Information From AntiVirus Vendors
|
|
|
|
|
Below you will find virus information from different antivirus vendors included in this Secunia Virus Profile. Information about the virus along with links to removal tools will be listed below when available.
The information provided is sorted by the date on which the information first became publicy available on the antivirus vendors' websites. The earliest available reports are displayed first. Please note timestamps are in GMT+1.
|

|
|
#1 - SYMANTEC
|
| |
|
|
Backdoor.Beasty.C
|
Severity:
1/5
|
File Size:
52,224 bytes
|
| |
|
|
Reported:
-
|
Last Update:
-
|
| |
Description:
Backdoor.Beasty.C is a backdoor Trojan that is similar to Backdoor.Beasty and Backdoor.Beasty.B.
|
| |
|
Full Report From Vendor
|
|
|
#2 - F-SECURE
|
| |
|
|
Trojan
|
Severity:
-
|
File Size:
-
|
| |
|
|
Reported:
2004-05-10 13:47
|
Last Update:
2004-10-01 05:43
|
| |
Description:
Trojan (generic description)
|
| |
|
Full Report From Vendor
|
|
|
#3 - SOPHOS
|
| |
|
|
Troj/Killav-I
|
Severity:
/5
|
File Size:
-
|
| |
|
|
Reported:
2004-05-18 15:31
|
Last Update:
2004-11-01 05:43
|
| |
Description:
|
| |
|
Full Report From Vendor
Removal Tool/Instructions
View/Hide ChangeLog
|
|
ChangeLog:
|
|
|
Changes are listed in chronological order with the latest changes first.
|
|
| |
|
|
2004-11-01 05:43
|
Severity was decreased from 2/5 to /5.
|
| |
|
|
2004-10-01 06:06
|
Severity was raised from N/A to 2/5.
|
| |
|
|
2004-10-01 06:06
|
Description was changed.
New: "N/A"
Old: "Troj/Killav-I attempts to terminate various security related programs."
|
| |
|
|
2004-05-18 16:06
|
Description was changed.
New: "Troj/Killav-I attempts to terminate various security related programs."
Old: "A detailed analysis will be published here shortly. Please check again later."
|
|
|
|
|
|
#4 - MCAFEE
|
| |
|
|
StartPage-FG
|
Severity:
2/7
|
File Size:
4,096 bytes
|
| |
|
|
Reported:
2004-10-25 14:06
|
Last Update:
2004-10-25 14:21
|
| |
Description:
Trojan Characteristics: When executed this trojan changes the default Home Page to http://search123.biz , which no longer seems to be available. A file called MSXMLFILT.DLL is added to C:\Windows\System. This file is also detected as StartPage-FG
|
| |
|
Full Report From Vendor
View/Hide ChangeLog
|
|
ChangeLog:
|
|
|
Changes are listed in chronological order with the latest changes first.
|
|
| |
|
|
2004-10-25 14:21
|
Description was changed.
New: "Trojan Characteristics: When executed this trojan changes the default Home Page to http://search123.biz , which no longer seems to be available. A file called MSXMLFILT.DLL is added to C:\Windows\System. This file is also detected as StartPage-FG"
Old: "N/A"
|
| |
|
|
2004-10-25 14:21
|
File size was changed.
New: "4,096 bytes"
Old: "N/A"
|
|
|
|
|
|
#5 - TREND MICRO
|
| |
|
|
TROJ_CRIMEA.A
|
Severity:
-
|
File Size:
-
|
| |
|
|
Reported:
2007-07-14 05:01
|
Last Update:
2007-07-29 05:37
|
| |
Description:
This Trojan may either be dropped or downloaded from remote site(s) by other malware. It may also arrive bundled with malware packages as a malware component or installed manually by a user.
It may also be downloaded unknowingly by a user when visiting malicious Web site(s).
Upon execution, this Trojan drops a .DLL file, which is detected by Trend Micro as TROJ_AGENT.WRG, in the Windows system folder.
It also modifies another .DLL file which is also found in the Windows system folder. The said file is used to load the dropped malicious .DLL file once a certain application uses the modified file.
|
| |
|
Full Report From Vendor
|
|
|
#6 - TREND MICRO
|
| |
|
|
TROJAN
|
Severity:
-
|
File Size:
-
|
| |
|
|
Reported:
2007-08-30 01:36
|
Last Update:
2007-09-03 05:42
|
| |
Description:
|
| |
|
Full Report From Vendor
View/Hide ChangeLog
|
|
ChangeLog:
|
|
|
Changes are listed in chronological order with the latest changes first.
|
|
| |
|
|
2007-09-03 05:42
|
Name was changed.
New: "TROJAN"
Old: "TROJ_NSPM.SI"
|
| |
|
|
2007-09-03 05:42
|
Description was changed.
New: "N/A"
Old: "This Trojan may be downloaded unknowingly by a user when visiting malicious Web sites.
It drops files/components, some of which are detected by Trend Micro as TROJ_NSPM.VV. As a result, routines of the dropped files are exhibited on the affected system."
|
| |
|
|
2007-08-30 02:52
|
Description was changed.
New: "This Trojan may be downloaded unknowingly by a user when visiting malicious Web sites.
It drops files/components, some of which are detected by Trend Micro as TROJ_NSPM.VV. As a result, routines of the dropped files are exhibited on the affected system."
Old: "N/A"
|
|
|
|
|
|
#7 - TREND MICRO
|
| |
|
|
TROJAN
|
Severity:
-
|
File Size:
-
|
| |
|
|
Reported:
2008-03-06 04:31
|
Last Update:
2008-04-04 05:32
|
| |
Description:
|
| |
|
Full Report From Vendor
View/Hide ChangeLog
|
|
ChangeLog:
|
|
|
Changes are listed in chronological order with the latest changes first.
|
|
| |
|
|
2008-04-04 05:32
|
Name was changed.
New: "TROJAN"
Old: "TROJ_MDROP.AH"
|
| |
|
|
2008-04-04 05:32
|
Description was changed.
New: "N/A"
Old: "This Trojan arrives as attachment to email messages spammed by another malware or a malicious user.
It may be dropped by other malware and may be downloaded unknowingly by a user when visiting malicious Web site(s).
It takes advantage of a known vulnerability in Microsoft Excel that allows remote code execution. More information on the said vulnerability is available in the following Microsoft Web page:"
|
| |
|
|
2008-03-14 04:41
|
Description was changed.
New: "This Trojan arrives as attachment to email messages spammed by another malware or a malicious user.
It may be dropped by other malware and may be downloaded unknowingly by a user when visiting malicious Web site(s).
It takes advantage of a known vulnerability in Microsoft Excel that allows remote code execution. More information on the said vulnerability is available in the following Microsoft Web page:"
Old: "This Trojan arrives as attachment to email messages spammed by another malware or a malicious user.
It may be dropped by other malware and may be downloaded unknowingly by a user when visiting malicious Web site(s).
It takes advantage of a known vulnerability in Microsoft Excel that allows remote code execution. More information on the said vulnerability is available here.
Once it successfully exploits the said vulnerability, it executes a shell code that allows it to drop any of several embedded files on the affected system, including BKDR_AGENT.SNI, BKDR_PCCLIEN.AAA, TROJ_SMALL.DCJ, and BKDR_PCCLIEN.AJT.
It then executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system."
|
| |
|
|
2008-03-06 05:51
|
Description was changed.
New: "This Trojan arrives as attachment to email messages spammed by another malware or a malicious user.
It may be dropped by other malware and may be downloaded unknowingly by a user when visiting malicious Web site(s).
It takes advantage of a known vulnerability in Microsoft Excel that allows remote code execution. More information on the said vulnerability is available here.
Once it successfully exploits the said vulnerability, it executes a shell code that allows it to drop any of several embedded files on the affected system, including BKDR_AGENT.SNI, BKDR_PCCLIEN.AAA, TROJ_SMALL.DCJ, and BKDR_PCCLIEN.AJT.
It then executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system."
Old: "N/A"
|
|
|
|
|
|
#8 - TREND MICRO
|
| |
|
|
TROJAN
|
Severity:
-
|
File Size:
-
|
| |
|
|
Reported:
2008-05-12 02:42
|
Last Update:
2008-05-14 02:42
|
| |
Description:
|
| |
|
Full Report From Vendor
View/Hide ChangeLog
|
|
ChangeLog:
|
|
|
Changes are listed in chronological order with the latest changes first.
|
|
| |
|
|
2008-05-14 02:42
|
Name was changed.
New: "TROJAN"
Old: "TROJ_DNSCHANG.CS"
|
| |
|
|
2008-05-14 01:42
|
Description was changed.
New: "N/A"
Old: "This Trojan may be dropped by other malware. It may be installed manually by a user. It may be downloaded unknowingly by a user when visiting malicious Web sites.
It creates folders.
It creates registry entries to enable its automatic execution at every system startup. It creates registry key(s)/entry(ies) as part of its installation routine.
It accesses Web sites to download file(s). As a result, malicious routines of the downloaded files are exhibited on the affected system.
It drops component files. Trend Micro detects one of the dropped files as ADW_ISMONITOR. As a result, routines of the dropped adware are also exhibited on the affected system.
It connects to Web sites."
|
| |
|
|
2008-05-12 03:06
|
Description was changed.
New: "This Trojan may be dropped by other malware. It may be installed manually by a user. It may be downloaded unknowingly by a user when visiting malicious Web sites.
It creates folders.
It creates registry entries to enable its automatic execution at every system startup. It creates registry key(s)/entry(ies) as part of its installation routine.
It accesses Web sites to download file(s). As a result, malicious routines of the downloaded files are exhibited on the affected system.
It drops component files. Trend Micro detects one of the dropped files as ADW_ISMONITOR. As a result, routines of the dropped adware are also exhibited on the affected system.
It connects to Web sites."
Old: "N/A"
|
|
|
|
|
|
Please note: The information that this Secunia Virus Profile is based on comes from a third party unless stated otherwise.
The grouping process is done completely automatically, therefore minor inconsistencies may occur. For more information about Secunia Virus Information, please read: About Virus Information.
|
|
|

|
 |
Secunia PSI Scan | Patch | Track Free Download
|
|
|
Secunia Poll
|
|
|
|
|
 |
|
|
Most Popular Advisories
|
|
|
|
|
|