Secunia - Stay Secure
Gartner
Home Corporate Website Jobs Mailing Lists RSS Blog Advertise
Software Inspectors
  Scan Online
  Personal (PSI)
  Network (NSI 2.0)

Solutions For
  Security Professionals
  Security Vendors

Free Solutions For
  Open Communities
  Journalists & Media

Secunia Advisories
  Search
  Historic Advisories
  Listed By Product
  Listed By Vendor
  Statistics / Graphs
  Secunia Research
  Report Vulnerability
  About Advisories

Virus Information
  Chronological List
  Last 10 Virus Alerts
  About Virus Information

Secunia Customers
  Customer Area


Beasty.C

Last Update: 2008-05-14 02:42
Risk Rating: Very Low Risk
Very Low Risk
Aliases: 2000
Backdoor.Beastdoor.192
Backdoor.Beasty.C
In
ME
No
NT
Server
StartPage-FG
TR/Small.DBY.LH.12
Troj/Dloader-DG
Troj/Killav-I
TROJAN
Trojan.Win32.Agent.ass
Trojan.Win32.Killav.q
Trojan.Win32.StartPage.jc
TROJ_CRIMEA.A
TROJ_STARTPGE.R
W32/Crimea.dr
XP
Information From AntiVirus Vendors


Below you will find virus information from different antivirus vendors included in this Secunia Virus Profile. Information about the virus along with links to removal tools will be listed below when available.

The information provided is sorted by the date on which the information first became publicy available on the antivirus vendors' websites. The earliest available reports are displayed first. Please note timestamps are in GMT+1.





#1 - SYMANTEC

Backdoor.Beasty.C

Severity:
1/5
File Size:
52,224 bytes
Reported:
-
Last Update:
-
Description:
Backdoor.Beasty.C is a backdoor Trojan that is similar to Backdoor.Beasty and Backdoor.Beasty.B.
Full Report From Vendor


#2 - F-SECURE

Trojan

Severity:
-
File Size:
-
Reported:
2004-05-10 13:47
Last Update:
2004-10-01 05:43
Description:
Trojan (generic description)
Full Report From Vendor


#3 - SOPHOS

Troj/Killav-I

Severity:
/5
File Size:
-
Reported:
2004-05-18 15:31
Last Update:
2004-11-01 05:43
Description:
Full Report From Vendor  Removal Tool/Instructions  View/Hide ChangeLog

ChangeLog:

Changes are listed in chronological order with the latest changes first.


2004-11-01 05:43 Severity was decreased from 2/5 to /5.


2004-10-01 06:06 Severity was raised from N/A to 2/5.


2004-10-01 06:06 Description was changed.

New:

"N/A"

Old:
"Troj/Killav-I attempts to terminate various
security related programs."


2004-05-18 16:06 Description was changed.

New:

"Troj/Killav-I attempts to terminate various
security related programs."

Old:
"A detailed analysis will be published here
shortly. Please check again later."



#4 - MCAFEE

StartPage-FG

Severity:
2/7
File Size:
4,096 bytes
Reported:
2004-10-25 14:06
Last Update:
2004-10-25 14:21
Description:
Trojan Characteristics: When executed this trojan changes the default Home Page to http://search123.biz , which no longer seems to be available. A file called MSXMLFILT.DLL is added to C:\Windows\System. This file is also detected as StartPage-FG
Full Report From Vendor  View/Hide ChangeLog

ChangeLog:

Changes are listed in chronological order with the latest changes first.


2004-10-25 14:21 Description was changed.

New:

"Trojan Characteristics: When executed this
trojan changes the default Home Page to
http://search123.biz , which no longer seems
to be available. A file called MSXMLFILT.DLL
is added to C:\Windows\System. This file is
also detected as StartPage-FG"

Old:
"N/A"


2004-10-25 14:21 File size was changed.

New:
"
4,096 bytes"

Old:
"N/A"



#5 - TREND MICRO

TROJ_CRIMEA.A

Severity:
-
File Size:
-
Reported:
2007-07-14 05:01
Last Update:
2007-07-29 05:37
Description:
This Trojan may either be dropped or downloaded from remote site(s) by other malware. It may also arrive bundled with malware packages as a malware component or installed manually by a user. It may also be downloaded unknowingly by a user when visiting malicious Web site(s). Upon execution, this Trojan drops a .DLL file, which is detected by Trend Micro as TROJ_AGENT.WRG, in the Windows system folder. It also modifies another .DLL file which is also found in the Windows system folder. The said file is used to load the dropped malicious .DLL file once a certain application uses the modified file.
Full Report From Vendor


#6 - TREND MICRO

TROJAN

Severity:
-
File Size:
-
Reported:
2007-08-30 01:36
Last Update:
2007-09-03 05:42
Description:
Full Report From Vendor  View/Hide ChangeLog

ChangeLog:

Changes are listed in chronological order with the latest changes first.


2007-09-03 05:42 Name was changed.

New:
"
TROJAN"

Old:
"TROJ_NSPM.SI"


2007-09-03 05:42 Description was changed.

New:

"N/A"

Old:
"This Trojan may be downloaded unknowingly by
a user when visiting malicious Web sites.
It drops files/components, some of which
are detected by Trend Micro as TROJ_NSPM.VV.
As a result, routines of the dropped files
are exhibited on the affected system."


2007-08-30 02:52 Description was changed.

New:

"This Trojan may be downloaded unknowingly by
a user when visiting malicious Web sites.
It drops files/components, some of which
are detected by Trend Micro as TROJ_NSPM.VV.
As a result, routines of the dropped files
are exhibited on the affected system."

Old:
"N/A"



#7 - TREND MICRO

TROJAN

Severity:
-
File Size:
-
Reported:
2008-03-06 04:31
Last Update:
2008-04-04 05:32
Description:
Full Report From Vendor  View/Hide ChangeLog

ChangeLog:

Changes are listed in chronological order with the latest changes first.


2008-04-04 05:32 Name was changed.

New:
"
TROJAN"

Old:
"TROJ_MDROP.AH"


2008-04-04 05:32 Description was changed.

New:

"N/A"

Old:
"This Trojan arrives as attachment to email
messages spammed by another malware or a
malicious user. It may be dropped by other
malware and may be downloaded unknowingly by
a user when visiting malicious Web site(s).
It takes advantage of a known vulnerability
in Microsoft Excel that allows remote code
execution. More information on the said
vulnerability is available in the following
Microsoft Web page:"


2008-03-14 04:41 Description was changed.

New:

"This Trojan arrives as attachment to email
messages spammed by another malware or a
malicious user. It may be dropped by other
malware and may be downloaded unknowingly by
a user when visiting malicious Web site(s).
It takes advantage of a known vulnerability
in Microsoft Excel that allows remote code
execution. More information on the said
vulnerability is available in the following
Microsoft Web page:"

Old:
"This Trojan arrives as attachment to email
messages spammed by another malware or a
malicious user. It may be dropped by other
malware and may be downloaded unknowingly by
a user when visiting malicious Web site(s).
It takes advantage of a known vulnerability
in Microsoft Excel that allows remote code
execution. More information on the said
vulnerability is available here. Once it
successfully exploits the said vulnerability,
it executes a shell code that allows it to
drop any of several embedded files on the
affected system, including BKDR_AGENT.SNI,
BKDR_PCCLIEN.AAA, TROJ_SMALL.DCJ, and
BKDR_PCCLIEN.AJT. It then executes the
dropped file(s). As a result, malicious
routines of the dropped files are exhibited
on the affected system."


2008-03-06 05:51 Description was changed.

New:

"This Trojan arrives as attachment to email
messages spammed by another malware or a
malicious user. It may be dropped by other
malware and may be downloaded unknowingly by
a user when visiting malicious Web site(s).
It takes advantage of a known vulnerability
in Microsoft Excel that allows remote code
execution. More information on the said
vulnerability is available here. Once it
successfully exploits the said vulnerability,
it executes a shell code that allows it to
drop any of several embedded files on the
affected system, including BKDR_AGENT.SNI,
BKDR_PCCLIEN.AAA, TROJ_SMALL.DCJ, and
BKDR_PCCLIEN.AJT. It then executes the
dropped file(s). As a result, malicious
routines of the dropped files are exhibited
on the affected system."

Old:
"N/A"



#8 - TREND MICRO

TROJAN

Severity:
-
File Size:
-
Reported:
2008-05-12 02:42
Last Update:
2008-05-14 02:42
Description:
Full Report From Vendor  View/Hide ChangeLog

ChangeLog:

Changes are listed in chronological order with the latest changes first.


2008-05-14 02:42 Name was changed.

New:
"
TROJAN"

Old:
"TROJ_DNSCHANG.CS"


2008-05-14 01:42 Description was changed.

New:

"N/A"

Old:
"This Trojan may be dropped by other malware.
It may be installed manually by a user. It
may be downloaded unknowingly by a user when
visiting malicious Web sites. It creates
folders. It creates registry entries to
enable its automatic execution at every
system startup. It creates registry
key(s)/entry(ies) as part of its installation
routine. It accesses Web sites to
download file(s). As a result, malicious
routines of the downloaded files are
exhibited on the affected system. It
drops component files. Trend Micro detects
one of the dropped files as ADW_ISMONITOR. As
a result, routines of the dropped adware are
also exhibited on the affected system.
It connects to Web sites."


2008-05-12 03:06 Description was changed.

New:

"This Trojan may be dropped by other malware.
It may be installed manually by a user. It
may be downloaded unknowingly by a user when
visiting malicious Web sites. It creates
folders. It creates registry entries to
enable its automatic execution at every
system startup. It creates registry
key(s)/entry(ies) as part of its installation
routine. It accesses Web sites to
download file(s). As a result, malicious
routines of the downloaded files are
exhibited on the affected system. It
drops component files. Trend Micro detects
one of the dropped files as ADW_ISMONITOR. As
a result, routines of the dropped adware are
also exhibited on the affected system.
It connects to Web sites."

Old:
"N/A"




Please note: The information that this Secunia Virus Profile is based on comes from a third party unless stated otherwise.

The grouping process is done completely automatically, therefore minor inconsistencies may occur. For more information about Secunia Virus Information, please read: About Virus Information.







Secunia PSI
Scan | Patch | Track
Free Download

Secunia Poll

Do you think it's important to read Setup/User Guides for applications for use within your network?


See Results   


Most Popular Advisories

1.
Debian OpenSSL Predictable Random Number Generator and Update
2.
Blender Multiple Temporary File Security Issues
3.
Kostenloses Linkmanagements cript Multiple Vulnerabilities
4.
Model Search "cat" SQL Injection Vulnerability
5.
Symantec Altiris Deployment Solution Multiple Vulnerabilities
6.
Rantx "logininfo" Security Bypass Vulnerability
7.
Linux Kernel Multiple Vulnerabilities
8.
Pet Grooming Management System "useradded.php" Security Bypass
9.
e107 BLOG Engine Plugin "rid" SQL Injection
10.
W1L3D4 Philboard Multiple SQL Injection Vulnerabilities





Vulnerability Management - Terms & Conditions - Copyright 2002-2008 Secunia - Compliance - Contact Secunia