Spurious interview offer - could be trojan

Percifal

New member
Joined
Oct 28, 2005
Messages
2
Reaction score
0
Points
0
Hi,
Got this reply in response to resume posted on 'net:

Hello,
Thank you for your resume. Please let me know the most convenient time
to contact you.

Learn more about us. View our
Electronic Presentation <http://tstriebel.com/download0805/adgf.exe>

Yours sincerely,

Nicole Chambers
Recruitment Officer
ADG Financial Inc


The downloaded exe prog immediately attempts to get on the net with your pc as a "server". It downloads to different folders. If you fail to search and delete all copies, it tries to get onto net as you start your pc.
Comments?
 
Thanks percifal, the person could have at least zipped the file to make it seem less suspicious :p.
 
One of the better tricks out there.

Beats the "DOWNLOAD THIS IMPORTANT DOCUMENT" email.
 
I just submitted a copy of it to Computer Associates, VirusBlokAda, and BitDefender. I'll post results here from their scans later on.

[Update:] I just got an e-mail back from Computer Associates.
The file "adgf.exe" looks suspicious. We will analyze this file and notify you of the conclusion. Until further analysis is complete, we recommend that you do NOT forward this file to anyone else. We also recommend that you pay special attention to any abnormal computer behaviour.
 
Last edited:
More results:
FILE
------------------------------------------------------------------------
adgf.exe
------------------------------------------------------------------------
The Windows PE (I386,EXE) file "adgf.exe" has been determined to be
malicious. Our researchers have analyzed the file and confirmed the
result.

Aliases reported by other AV products are listed here:
(Generic Keylogger.d)
 
Back
Top