« Attackers Triple Play to Deliver Zero Days | Main | /.sys/ Folders and Malware »
Monday
Mar292010

Adobe Update Trojan Claims are Invalid

Over the weekend, Vietnamese antivirus vendor Bkis blogged about new malware that was allegedly overwriting the legitimate adobeupdater.exe file. From the Bkis blog:

Once having infected victims’ computers, malware will overwrite such update programs.

and

The malware overwrites AdobeUpdater.exe file in the folder Adobe/Reader 9.0/Reader.

The valid AdobeUpdate.exe isn't located in in the folder Adobe/Reader 9.0/Reader or more accurately, C:\Program Files\Adobe\Reader x.x. It's usually located in C:\Program Files\Common Files\Adobe\Updater5.

What is located in the C:\Program Files\Adobe\Reader x.x folder is AdobeUpdater.dll (note that it's a DLL which means it would not be overwritten if an .exe with the same name were dropped to the folder). And in version 9.x, (the example given in the Bkis post), the file is not only in an entirely different folder, it's also named adobe_updater.exe and not adobeupdater.exe.

In short, there's currently no evidence that this malware is overwriting or even interfering with Adobe updates. Remember, diagnosing infections can be a lot like real estate: it's all about location, location, location.

 

Reader Comments

There are no comments for this journal entry. To create a new comment, use the form below.

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>