Encyclopedia

FakeDeath.A

 
Threat LevelLow threatDamageHighDistributionNot widespread
Common name:FakeDeath.A
Technical name:W32/FakeDeath.A.worm
Threat level:Medium
Type:Worm
Effects:  

It reaches the computer passing itself off as some news related to the fake death of Fidel Castro. It downloads several variants of Trojans belonging to the Banker family to the affected computer and distribute them through the shared directories belonging to several programs such as mIRC, eDonkey or KaZaA.

Affected platforms:

Windows 2003/XP/2000/NT/ME/98/95

First detected on:March 7, 2008
Detection updated on:March 11, 2008
StatisticsNo
Yes, using TruPrevent Technologies

Brief Description 

    

FakeDeath.A is a worm that downloads several variants of Trojans belonging to the Banker family to the affected computer. Then, these files are distributed through the shared directories belonging to several programs such as mIRC, eDonkey or KaZaA.

The variants belonging to the Banker family are designed to obtain confidential information, such as passwords, from the affected computer.

Additionally, it carries out several modifications in the Windows Registry, which prevent the user from carrying out the following actions, among others:

  • Viewing the processes that are being run through the Task Manager.
  • Turning off the computer and logging off, as it disables both options of the Start menu.

FakeDeath.A spreads via shared and mapped drives, making copies of itself in them.

Visible Symptoms 

    

FakeDeath.A is easy to recognize once it has affected the computer, as it reaches the computer in a file with the icon of a picture:

Icon with which FakeDeath.A reaches the computer

If this file is run, the user will be redirected to a website displaying some news published in 1997 related to the fake death of Fidel Castro:

Image of the website displaying the fake news

Last updated:  11/03/2008 

Virus News

3/10/09.-More than 10 Million Worldwide Were Actively Exposed to Identity Theft in 2008

3/5/09.-Cyber-crooks manipulate Internet searches to sell fake antivirus products

3/2/09.-VideoPlay adware infections grew 400% in February through malicious use of Web 2.0 pages

[+ Noticias]