Removal Instructions

If your computer has not been protected with anti-virus software and has been infected with malware, you will need to take the following actions to delete this:

  1. Delete the original exploit file (its location on the infected computer will depend on how the program got onto the computer).
  2. Clear the Temporary Internet Files directory containing the infected files (How to delete infected files in the Temporary Internet Files folder?):
    %Temporary Internet Files%

  3. Update Adobe Reader and Acrobat or install updates:
  4. Run a full Kaspersky Antivirus scan of the computer with updated antivirus databases (download trial version).

MD5: 6209f86a1ba16c7c1ca0008eb49dd1d6
SHA1: 80816defd9dd9b6b59aed980c75df745717f0c89


The malicious XFA form content is initialized and launched after opening a specially created infected PDF document containing this form. As the "initialize" event handler in the XFA form, it uses obfuscated malicious Java Script. After removing the obfuscation, the trojan uses the vulnerability which arises on account of over-filling the buffer when incorrectly processing arguments in "libtiff.dll" (CVE-2010-0188) to download the file located at the following link:


The trojan then saves the file in the browser's temporary file directory:
%Temporary Internet Files%\<name of_temporary_file>

After successfully saving the file, the infected file is then launched for execution. The link did not work when creating the description. Vulnerable products include Adobe Reader and Acrobat 8 (up to version 8.2.1) and 9 (up to version 9.3.1).

Technical Details

An exploit that uses the vulnerabilities in Adobe – Reader and Acrobat products for its implementation on the user's computer. The file is an XFA (XML Forms Architecture) containing malicious Java Script. 43051 bytes.