JS_DLOADER.SMGA

By LoneStar in Trojans | 8 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
More... More

JS_DLOADER.SMGA Description

JS_DLOADER.SMGA is a JavaScript Trojan that exploits a vulnerability CVE-2012-1875 in Internet Explorer, which is addressed in MS12-037 bulletin. The certain vulnerability is known as (MS12-037) Cumulative Security Update for Internet Explorer (2699988), which is used to drop possibly infectious files. When JS_DLOADER.SMGA exploits the vulnerability, it drops and runs infected files on the affected PC. JS_DLOADER.SMGA can spread via remote insecure websites. JS_DLOADER.SMGA also invades the particular websites for distributing malicious files. JS_DLOADER.SMGA can distribute another malware infection, a backdoor Trojan found as BKDR_AGENT.BCSG. Unlike exploit document files, JS_DLOADER.SMGA collects the operating system version and language used in the targeted PC by using a simple script. When JS_DLOADER.SMGA exploits CVE-2012-1875, it runs a Heap Spray method for executing a specific shellcode. Though JS_DLOADER.SMGA successfully exploits CVE-2012-1875, its code cannot jump to the specified Heap Spray because of Data Execution Prevention (DEP) found on affected programs such as IE8 and IE9. To evade DEP, this exploit uses return-oriented programming (ROP) method to check system environment like operating systems and languages. JS_DLOADER.SMGA uses a specific script in order to recognize the loaded modules in memory at different addresses, which are based on operating system and language information. Then, depending on the affirmed system information, JS_DLOADER.SMGA creates a specific ROP code.

Type: Trojans

How Can You Detect JS_DLOADER.SMGA?

JS_DLOADER.SMGA Removal Details

JS_DLOADER.SMGA creates the following files in the system:

  • %User Temp%\log.gif

Important Article Disclaimer

ESG Support Center

This entry was last updated on 06/29/12 and posted on 06/29/12. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.