Backdoor Sneaks into Computers through Japanese Text Editor

Softarea51.com is your source for all the latest computer technology and software related press releases.
Browse our archive for more press releases!

Released on: 23, August 2006
, Author: Manish
, Audience: Computers related

Recommended: Click here to run a Free driver update scan »


Security experts at MicroWorld Technologies inform infected JTDfiles are smartly employed in exploiting a recently found vulnerability in Ichitaro,in order to spread a covert backdoor named  Win32.Papi.aÂ', thus orchestratingtargeted computer attacks in the land of rising sun. Justsystems, the makers ofIchitaro, has issued a patch for the flaw, downloadable athttp://www.justsystem.co.jp /info/pd6002.html

The backdoor penetration is carried out using a malicious JTD file that backpacks aTrojan Dropper named  Ichitaro.Tarodrop.aÂ'. The Trojan Dropper exploits a UnicodeStack Overflow Vulnerability in the text editing software to execute its code on thesystem and to extract a backdoor named  Win32.Papi.aÂ'.

Once activated, Win32.Papi.a installs itself in the system registry, initiates aService named CAPAPI, drops its main DLL file which is then injected into therunning processes of the compromised computer. It establishes a connection with theremote Server on port 8080 and listens for commands from the remote attacker.

The backdoor can harvest system information, stop and start processes, takescreenshots of the desktop and send them to the attacker, download files from thenet and execute them, capture network user information, log off current user, searchdisks for files, create and move directories and restart the victimÂ's machine. UsingWin32.Papi the attacker takes over the targeted machine completely to conduct arange of online criminal activities.

 ItÂ's not the first time text editors are used in smuggling malware into usercomputers. In May, we had reported about  Win32.GusiÂ' that was spread via aspecially created Word file that exploited a security flaw in Microsoft Word, whichincidentally was reported the first time in Japan with the attacker possibly sittingin China, says Sunil Kripalani, Vice President, Global Sales and Marketing,MicroWorld Technologies.

MicroWorld has developed the WorldÂ's most advanced Security Solutions, eScan andMailScan, that consistently maintain the fastest malware detection and preventionrate. Combining the superior AntiVirus System with its unique MWL technology,MicroWorld protects users from a range of zero-day threats of this nature.

The CEO of MicroWorld Technologies, Govind Rammurthy, gives a broader view on theissue  Trojans and Backdoors that exploit vulnerabilities in system and applicationsoftware can spread quiet fast and deliver their payload without much of userintervention. They are like camouflaged infiltrators who sneak into your homelandand expand their deadly mission under the cover of darkness. And this particularcase goes well to underline what we have been advocating all along, that users needto update timely security patches not just for their Operating Systems, but forapplication software programs as well.Â

MicroWorldMicroWorld (www.mwti.net ) is the developer of the world's first Real-TimeAnti-Virus and Content Security software eScan for desktops and servers. Itscommunication security software, MailScan is the first comprehensive e-mail scannerfor your SMTP/POP3 Mail Server. MicroWorld Winsock Layer (MWL) is the revolutionarytechnology underlying these products, powering them to several certifications andawards by some of the most prestigious testing bodies, notable among them beingVirus Bulletin, Checkmark, TUCOWS, Red Hat Ready, and Novell Ready. Combining theirpowerful scanner with MWL technology, MicroWorld solutions provide a Real-TimeProactive security for your systems. For network security of enterprises, eConcealFirewall is the latest powerful offering from MicroWorld.

For more information write to manish@mwti.net


Source: Express-Press-Release.com
Related downloads


EditPlus is a text editor, HTML editor and programmers editor for Windows. While it can serve as a good Notepad replacement, it also offers many powerful features for Web page authors and programmers.

This complete rich text editor builds rich text executables using DERT. You can use it as rich text to web page or text to PDF converter. Also, Text To Speech is supported. A unique solution that combines advanced features into a fun to use program.

EditPad Pro is a powerful and versatile text editor or word processor, designed to make text editing as convenient as possible. Write and edit all your text files such as source code, scripts, web sites, logs, letters, memos, reports, articles, etc.

automate typing of repetitive phrases in any text editor

Spell check text, paragraph or document from any application, e-mail, editor or database; system-wide on-the-fly spell check; over 25 languages, medical, legal. Improved Compatibility Mode for MS Word, Internet Explorer, Outlook Express and more.

Unicode Image Maker is designed for situations when you need to use unicode text in a program but its not supported natively; you can use this tool to create a graphics image of your unicode text and embed the image instead.

Powerful text Uniocde editor with syntax highlighting, text folding, text structure tree view... The unique and more important feature is 100% customizable lexer, so you can adjust it for any type of text file. Fast working even with huge files.

Text editor for Windows Mobile based Smartphone's that can view or send text as multiple SMS messages or as e-mail attachments. Support for search, cut, copy, paste, delete, undo, use font of any size, recent file list, file associations, and more.

Text editor for Windows Mobile based Smartphone's that can view or send text as multiple SMS messages or as e- mail attachments. Support for search, cut, copy, paste, delete, undo, use font of any size, recent file list, file associations, and more.

TextIt handle unformatted text and works well with files over the 64kB limitation in e.g. notepad.
The most common utilities are included, like: Search, Replace, Undo, Redo, Print and Run.
Softarea51.com RSS Feed

Get RSS updates on latest computer technology and software related press releases Subscribe to Latest Press Releases RSS feed    Subscribe



You are welcome to include these headlines in your own pages. If you want to find out how to parse this RSS file please read our tutorial How to parse RSS feeds with PHP.