GCIH · Question #174
Which of the following Trojans is used by attackers to modify the Web browser settings?
The correct answer is C. WMA/TrojanDownloader.GetCodec. WMA/TrojanDownloader.GetCodec disguises itself as a media file and, once executed, modifies web browser settings to redirect users to attacker-controlled sites.
Question
Which of the following Trojans is used by attackers to modify the Web browser settings?
Options
- AWin32/FlyStudio
- BTrojan.Lodear
- CWMA/TrojanDownloader.GetCodec
- DWin32/Pacex.Gen
How the community answered
(33 responses)- A6% (2)
- B3% (1)
- C88% (29)
- D3% (1)
Why each option
WMA/TrojanDownloader.GetCodec disguises itself as a media file and, once executed, modifies web browser settings to redirect users to attacker-controlled sites.
Win32/FlyStudio is a backdoor trojan that provides remote access capabilities but is not specifically associated with modifying web browser settings.
Trojan.Lodear is primarily a dropper that downloads and installs additional malicious files to disk; it does not specifically target browser configuration.
WMA/TrojanDownloader.GetCodec spreads as a Windows Media Audio file that prompts users to install a fake codec update. Once the malicious payload executes, it alters browser configuration values such as the home page and default search provider, redirecting victims to attacker-controlled sites and enabling further compromise.
Win32/Pacex.Gen is a generic heuristic detection for obfuscated or packed malware families and is not specifically known for browser hijacking behavior.
Concept tested: Browser-hijacking trojan identification
Source: https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=TrojanDownloader%3AWMA%2FGetCodec
Topics
Community Discussion
No community discussion yet for this question.