Home Malware Programs Trojans TROJ_MDIEXP.QYUA

TROJ_MDIEXP.QYUA

Posted: January 27, 2012

Threat Metric

Ranking: 6,455
Threat Level: 2/10
Infected PCs: 84,826
First Seen: January 27, 2012
Last Seen: March 7, 2025
OS(es) Affected: Windows

TROJ_MDIEXP.QYUA is a midi (a simple music format) file exploit that's hosted by malicious sites like hxxp://images.[CENSORED]p.com/mp.html. TROJ_MDIEXP.QYUA, in conjunction with other exploits, is used to install a Trojan or other PC threat onto your computer without any signs that this has occurred. Keeping your OS, security software and browser all up-to-date will help to reduce the possibility of TROJ_MDIEXP.QYUA being involved in an attack on your PC, since TROJ_MDIEXP.QYUA's exploit has been patch-fixed by Microsoft in early January. Since TROJ_MDIEXP.QYUA's ultimate payload, TROJ_DLOAD.QYUA, lacks visible symptoms and includes rootkit capabilities, SpywareRemove.com malware researchers recommend that you treat any potential contact with TROJ_MDIEXP.QYUA as a serious threat to your PC and apply anti-malware software to delete TROJ_DLOAD.QYUA and other remnants of a TROJ_MDIEXP.QYUA attack from your hard drive.

TROJ_MDIEXP.QYUA – the Threat Underneath Its Jaunty Little Tune

TROJ_MDIEXP.QYUA is a malicious midi file that's created to take advantage of the CVE-2012-0003 exploit, a vulnerability that was removed in a Microsoft patch on January 10th. SpywareRemove.com malware experts have found that TROJ_MDIEXP.QYUA tends to be coupled with a JavaScript-based PC threat, JS_EXPLT.QYUA, that is used in conjunction with TROJ_MDIEXP.QYUA to install Trojans like TROJ_DLOAD.QYUA. The web page that hosts these exploits is also identified by a specific label, HTML_EXPLT.QYUA. A combination of safe web-surfing habits, updating your OS and possessing effective anti-malware programs can be used to prevent TROJ_MDIEXP.QYUA from successfully installing anything, including TROJ_DLOAD.QYUA, on your PC.

Since midi files are supported by default Windows software, directly stopping TROJ_MDIEXP.QYUA can be considered difficult unless you've patched your PC to remove TROJ_MDIEXP.QYUA's exploit. SpywareRemove.com malware experts also note that only specific versions of Windows are in danger of TROJ_MDIEXP.QYUA's attack – specifically, Service Pack 2 for Windows XP, Vista, Server 2003 or Server 2008, as well as Service Pack 3 for Windows XP. You may also protect yourself against TROJ_MDIEXP.QYUA in an indirect fashion by avoiding casual usage of JavaScript on suspicious sites, since TROJ_MDIEXP.QYUA requires assistance from a second and Java-based exploit to accomplish its attack.

TROJ_MDIEXP.QYUA – a Tune without Shame That Will Render Your PC without Security

Trojans that are installed by TROJ_MDIEXP.QYUA have been noted for advanced rootkit characteristics that allow them to conceal their presence from casual detection as well as load themselves automatically (assuming that your PC launches with normal boot parameters). If your PC has been subjected to a TROJ_MDIEXP.QYUA attack that hasn't been thwarted by patches or anti-malware products, SpywareRemove.com malware researchers warn you to be ready for the following dangers, at a minimum:

  • The possibility of a backdoor that allows criminals to control your PC.
  • The installation of other PC threats that can vary due to configuration instructions from a remote server.
  • The presence of a hidden browser process that can be used to launch other attacks or take up excessive RAM (thus impacting the performance of your computer).
  • Attacks against various brands of PC security software, presumably to prevent them from removing TROJ_MDIEXP.QYUA's payload.

Technical Details

Additional Information

The following URL's were detected:
oackoubs.com
Loading...