Discovered: June 24, 2007
Updated: June 25, 2007 8:50:26 AM
Type: Trojan
Infection Length: 123,665 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Trojan.Lhdropper is a Trojan horse that drops malicious files by exploiting a vulnerability in Lhaca, a freeware application that can compress and decompress LZH archive files.
Further Reading:To find out more about this threat, please read the Symantec Security Response blog entry
Beware of LZHProtection
-
Initial Rapid Release version June 25, 2007 revision 003
-
Latest Rapid Release version April 12, 2009 revision 049
-
Initial Daily Certified version June 25, 2007 revision 018
-
Latest Daily Certified version June 25, 2007 revision 003
-
Initial Weekly Certified release date June 27, 2007
Click for a more detailed description of Rapid Release and Daily Certified virus definitions.
Threat Assessment
Wild
-
Wild Level: Low
-
Number of Infections: 0 - 49
-
Number of Sites: 0 - 2
-
Geographical Distribution: Low
-
Threat Containment: Easy
-
Removal: Easy
Damage
-
Damage Level: Low
-
Payload: Drops malicious files by exploiting a vulnerability in Lhaca application.
Distribution
Writeup By: Masaki Suenaga