Malware targets Internet Explorer 7 Bug
A new strain of malware has been attacking users of Internet Explorer 7 (IE7), according to TrendMicro.com website. The new virus uses a bug in IE7 that occurs when the operating system tries to access deleted objects. This means the criminals can remotely execute arbitrary codes to take screen shots, download personal information, log-in’s, etc to their remote servers. It also creates a hidden Internet Explorer window which connects to a website to listen for commands.
The virus starts with a .DOC file cloaked as a XML_DLOADR.A which downloads a back door detected as BKDR_AGENT.XZMS, which installs a .DLL file that has information capabilities. The .DLL file sends your stolen information to the bad guys URL via port 443.
IE7 is currently being used by an estimate of one in every four Web users, that’s a lot of people. Meanwhile, Trend Micro Engineers are working hard on the details of this threat and posting updates as information trickles in.
Seems up-to-date Smart Protection Network users are safe from the threat, Nevertheless IE7 users should immediately proceed to patch their systems.
[via TrendMicro]

