Alert level

Trojan:Win32/Giframe.A

(?)

Encyclopedia entry
Updated: Apr 17, 2011  |  Published: Aug 06, 2010

Aliases
  • IFrame.gen (Command)
  • GIF/Iframe!generic (CA)
  • Trojan.DL.Giframe.a (Rising AV)
  • Mal/Iframe-F (Sophos)
  • Trojan-Clicker.HTML.IFrame (Sunbelt Software)
  • TROJ_IFRAME.CP (Trend Micro)

Alert Level (?)
Severe

Antimalware protection details
Microsoft recommends that you download the latest definitions to get protected.
Detection initially created:
Definition: 1.61.411.0
Released: Jun 26, 2009


 

Summary

Trojan:Win32/Giframe.A  is a detection for GIF files that contain malicious IFrame tags.


 

Symptoms

There are no common symptoms associated with this threat - links are activated within IFrames while viewing web content on maliciously modified pages. Alert notifications from installed antivirus software may be the only symptoms.


 

Technical Information (Analysis)

Trojan:Win32/Giframe.A may arrive in a computer when a user opens webpages that contains specially-crafted GIF files. Files detected as Trojan:Win32/Giframe.A contain malicious IFrame tags that point to certain URLs.
 
Some of the URLS that these malicious IFrame tags point to are:
 
  • dhtianyu.net
  • xaioyx365.com.cn
  • aaa.369678.cn
  • k.thec.cn
  • m586m.free.rdear.com
  • 66ki.cn
 
Analysis by Daniel Radu


 

Prevention



 

Recovery

To detect and remove this threat and other malicious software that may be installed in your computer, run a full-system scan with an up-to-date antivirus product such as the following:
 
 
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.

Provide feedback