Trojan.Pidief.E

Risk Level 1: Very Low

Printer Friendly Page

Discovered: February 12, 2009
Updated: February 12, 2009 5:18:24 PM
Type: Trojan
Infection Length: 827,308 bytes
Systems Affected: Windows XP, Windows Vista, Windows 2000
CVE References: CVE-2009-0658

Trojan.Pidief.E is a Trojan horse that attempts to exploit the Adobe Reader PDF File Handling Remote Code Execution Vulnerability (BID 33751) in order to drop more files on to the compromised computer.

Further Reading:
For more information, please read the following:
Targeted PDFs Used as Exploits

Protection

  • Initial Rapid Release version February 12, 2009 revision 023
  • Latest Rapid Release version February 5, 2010 revision 008
  • Initial Daily Certified version February 12, 2009 revision 038
  • Latest Daily Certified version February 5, 2010 revision 032
  • Initial Weekly Certified release date February 18, 2009

Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Easy

Damage

  • Damage Level: Low
  • Payload: Drops files on to the compromised computer.

Distribution

  • Distribution Level: Low
  • Target of Infection: Exploits a remote Buffer Overflow vulnerability in Adobe Acrobat Reader 8 and 9.

Writeup By: Elia Florio
Search by name
Example: W32.Beagle.AG@mm
Learn more about Zero-Day / Operation Aurora / Hydraq
Symantec DeepSight Screensaver