Home Malware Programs Trojans TSPY_FAREIT.SMC

TSPY_FAREIT.SMC

Posted: October 17, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 63
First Seen: October 17, 2012
OS(es) Affected: Windows

TSPY_FAREIT.SMC is a Trojan downloader that installs variants of Zeus spyware onto the affected computers. TSPY_FAREIT.SMC's payloads then proceed to steal confidential information, with an emphasis on e-mail addresses, passwords, bank account information and cookie-stored data. Even by itself, TSPY_FAREIT.SMC has been found to be able to steal account and login information for various file managers and FTP clients. The latest TSPY_FAREIT.SMC attacks, as analyzed by SpywareRemove.com malware experts, utilize e-mail spam messages that encourage victims to download TSPY_FAREIT.SMC as a fake update for Adobe Flash. Given the advanced and incredibly invasive nature of TSPY_FAREIT.SMC's payload, it's highly encouraged that you avoid infections in the first place, but advanced anti-malware products can be used to remove TSPY_FAREIT.SMC and its Zeus Trojans if this is necessary.

TSPY_FAREIT.SMC and the Business Transaction that Definitely Should Be Left Waiting

Like many other PC threats, strategies for distributing TSPY_FAREIT.SMC use e-mail spam, but SpywareRemove.com malware researchers have noted two separate templates being used for TSPY_FAREIT.SMC's e-mail messages. One e-mail for TSPY_FAREIT.SMC attempts to trick victims with a fake PayPal transaction notice, while a second e-mail uses a fake WebEx conference invitation. In either case, clicking on the provided link will take you to a fake update page for Adobe Flash.

SpywareRemove.com malware researchers emphasize that this fake Flash web page has been designed to look nearly identical to that of the normal update page for Adobe Flash, including Adobe's characteristic drop-down menu. However, if you try to update Flash, your PC will, instead, be infected with TSPY_FAREIT.SMC.

Besides conducting its own attacks, TSPY_FAREIT.SMC also installs one of two other PC threats: TSPY_ZBOT.LAG or TSPY_ZBOT.AMM. These variants of the well-known Zeus spyware are designed to target and steal bank account information, even though SpywareRemove.com malware analysts also notice that FTP client data and other types of sensitive information are also at risk from attacks by TSPY_FAREIT.SMC and its payload.

Making Sure Your Account isn't TSPY_FAREIT.SMC's Next Victim

Because TSPY_FAREIT.SMC's latest attacks have coincided with a recent Adobe Flash update, you should be particularly careful to avoid installing Flash updates from dangerous sources. Always navigate to the desired site for updates without using potentially-compromised links or other sources that are often used for malware distribution.

A successful TSPY_FAREIT.SMC infection has a very high chance of stealing many different passwords and login names from your computer. After you've used anti-malware products to alleviate the TSPY_FAREIT.SMC infection, you should strongly consider changing all important passwords to prevent criminals from hijacking your accounts.

SpywareRemove.com malware analysts also mention that having strong passwords, first of all, is a fine idea to fight TSPY_FAREIT.SMC, which also contains brute-force-based password-cracking attacks that could be used to compromise password-protected resources. Since this method uses a preset list of easily-guessed password combinations, the stronger your password is, the safer your PC is from TSPY_FAREIT.SMC.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%User Temp%\{RANDOM NUMBER}.exe File name: %User Temp%\{RANDOM NUMBER}.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
update_flash_player.exe File name: update_flash_player.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Loading...