We found a new one today that’s pretty interesting.
Detected by TrojanHunter as TrojanClicker.VB.395, this piece of malware purports to be an updater for your Adobe Flash installation. When run, it goes through the motions of updating the Flash player, and most users will think nothing of it. The installer for this seems to be spread via forum posts that use JavaScript to link to the malware.
Update: This is what the malicious pop-up looks like:
Cheekily, the malware asks you to shut down Firefox if it’s running during the installation. The reason for this is that it installs a Firefox plugin. Upon restarting Firefox after the malware is installed you will see this:
This shows that a new Firefox extension has been installed. And it does look pretty legitimate, doesn’t it? The GUID for the extension is 191d3f14-ff4c-4895-bdea-db54526cb49a
and the extension’s name and version number is “Adobe Flash Player 0.2″.
So what does this extension do? It, in conjunction with a trojan executable named smc.exe, monitors all your Google searches and sends them off to the server msjupdate.com where the keywords you search for will be stored in a database. The Firefox extension will inject ads into the web pages you view based on the keywords, but the bigger threat to privacy is of course that anything you search for will be recorded at a malicious server. Many users will Google their own name from time to time, which makes it possible to identify individual users along with their search queries.
So how do you know if you have this trojan on your system? Any of these signs indicate that you’re infected:
A running process named smc.exe
Edit: Sygate Firewall also uses this process name so this is not a reliable indicator of infection.
- A Firefox plugin named “Adobe Flash Player 0.2″
- Having recently installed a file called install_flash_player.exe or Install_Flash.exe from an unknown source
Of course, TrojanHunter detects this as well so you can use it to check for and clean out any infection.
Update: Further research has shown that this malware also monitors all URLs you visit in Internet Explorer and submits them to the malware creator’s server. So this is worse than we initially thought. If you have this on your system then you basically have no privacy left.