
A second Trojan used in the latest zero-day attack against Microsoft Office contains <A HREF="http://www.eweek.com/article2/0,1895,1992128,00.asp?kc=EWNAVEMNL072106EOAD">characteristics that pinpoint corporate espionage</A> as the main motive, according to virus hunters tracking the threat. According to an alert from Symantec, a backdoor called Trojan.Riler.F is installing itself as a layered service provider, or LSP, allowing it access to every piece of data entering and leaving the infected computer. An LSP is a legitimate system driver linked deep into the networking services of Windows. It is used primarily to allow the operating system to connect to other computers, but virus writers have found a way to make malicious programs work as LSPs to hijack sensitive data during transmission.