Home Malware Programs Trojans Exploit:Win32/Pdfjsc.ADQ

Exploit:Win32/Pdfjsc.ADQ

Posted: November 8, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 550
First Seen: November 8, 2012
Last Seen: May 5, 2020
OS(es) Affected: Windows

Exploit:Win32/Pdfjsc.ADQ is a Javascript Trojan that propagates as a malicious .PDF file that exploits a vulnerability in Adobe Acrobat and Adobe Reader. The vulnerabilities, discussed in CVE-2010-0188, enable Exploit:Win32/Pdfjsc.ADQ to drop and execute arbitrary files. Adobe Acrobat 8 and Adobe Reader 8 earlier than 8.2.1 and Adobe Acrobat 9 and Adobe Reader 9 earlier than 9.3.1 are vulnerable to this exploit. PC users can unknowingly infect their computers with Exploit:Win32/Pdfjsc.ADQ when visiting a hijacked website that hosts the file, and has been identified to be delivered via the 'Blackhole exploit pack'. The .PDF file includes a malicious JavaScript that exploits a vulnerability, discussed in CVE-2010-0188. If Exploit:Win32/Pdfjsc.ADQ successfully exploits an affected computer, it executes shellcode to drop and install other malware threats. Exploit:Win32/Pdfjsc.ADM attempts to download files from the certain servers.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



wpbt0.dll File name: wpbt0.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
pear.exe File name: pear.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
mrz.exe File name: mrz.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Loading...