Content

Downloader-BW.b

Type
Trojan
SubType
Downloader
Discovery Date
03/18/2003
Length
3,072 bytes
Minimum DAT
4253 (03/19/2003)
Updated DAT
4363 (05/26/2004)
Minimum Engine
5.1.00
Description Added
03/18/2003
Description Modified
04/01/2003 1:59 PM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This detection is for a downloader trojan which downloads and installs a remote executable. At the time of writing, the remote file was unavailable rendering this downloader useless. The trojan bears similarities with a previous variant.

The downloader is likely to be received via an email masquerading as a greetings card. The trojan was spammed out in this manner recently. When the downloader is run on the victim machine, a fake error message is displayed:

[Error on line 25: invalid object. Do you want to debug?]

It then attempts to download a remote executable from :

http://view-blocked-yahoo.com/sysman32.exe

The SYSMAN32.EXE file is downloaded to %SysDir% as SYSMAN32.EXE, and a Registry key is added to launch it at subsequent system startup. For example:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"SystemManager" = C:\WINNT\System32\sysman32.exe

Symptoms

Existence of the file SYSMAN32.EXE in %SysDir% coupled with the Registry hook detailed above.

Method of Infection

The downloader trojan is likely to be received via an email masquerading as a greetings card. The downloader downloads and installs a remote executable to %SysDir% as SYSMAN32.EXE.

Removal

All Users:
Use specified engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

This is a trojan detection. Unlike viruses, trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.

Aliases

  • Trojan.GreetCard.3072 (Dialogue Science)
  • TrojanDownloader.Win32.Greetyah (AVP)

Characteristics

Characteristics -

This detection is for a downloader trojan which downloads and installs a remote executable. At the time of writing, the remote file was unavailable rendering this downloader useless. The trojan bears similarities with a previous variant.

The downloader is likely to be received via an email masquerading as a greetings card. The trojan was spammed out in this manner recently. When the downloader is run on the victim machine, a fake error message is displayed:

[Error on line 25: invalid object. Do you want to debug?]

It then attempts to download a remote executable from :

http://view-blocked-yahoo.com/sysman32.exe

The SYSMAN32.EXE file is downloaded to %SysDir% as SYSMAN32.EXE, and a Registry key is added to launch it at subsequent system startup. For example:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"SystemManager" = C:\WINNT\System32\sysman32.exe

Symptoms

Symptoms -

Existence of the file SYSMAN32.EXE in %SysDir% coupled with the Registry hook detailed above.

Method of Infection

Method of Infection -

The downloader trojan is likely to be received via an email masquerading as a greetings card. The downloader downloads and installs a remote executable to %SysDir% as SYSMAN32.EXE.

Removal -

Removal -

All Users:
Use specified engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A