“You’ve got a fax” emails contains a trojan
September 13, 2010 4 Comments
MX Lab just intercepted some samples of a new trojan attached to emails with the subject “You’ve got a fax”. The body of the message contains an embedded JPEG file and attached a ZIP file.

It looks like it is sent from the online service eFax (http://www.efax.com) but it’s not. The email address [email protected] is spoofed.
The ZIP file has the name eFax39106.zipand it contains the 40 kB large file efax871291.exe - please note that the numbers may vary.
The following files are installed on the infected system:
%Temp%\1.tmp
%System%\fvfj.sxo
The following registry key is created:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\idid
The following registry key is modified:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
Shell =
At the time of writing, only 5 of the 43 AV engines at Virus Total did detect the trojan. The trojan is known as Gen:Trojan.Heur.FU.cC0@a4DqMHii (BitDefender), W32/Trojan3.BZM (F-Prot) or W32/Obfuscated.BQ!genr (Norman).
Virus Total permlink and MD5: f4dd8d5788d0f227bc51cd28b5892561.
