Content

Downloader-HU

Type
Program
SubType
Downloader
Discovery Date
02/13/2004
Minimum DAT
4325 (02/18/2004)
Updated DAT
4539 (07/20/2005)
Minimum Engine
5.1.00
Description Added
02/26/2004
Description Modified
03/25/2004 10:55 PM (PT)

Tab Navigation

Characteristics

This is not a virus or trojan. It is a direct-marketing adware application.  It downloads other adware and Internet game applications.

When run, it copies itself to %SysDir%\VERSION.exe, where %SysDir% is the Windows system directory.

It creates the following registry key to load itself at Windows startup:

  •  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    "version" = %SysDir%\VERSION.exe

It then connects to two websites, downloads several adware and Internet game applications to the local machine. 

Users who would like to check for the presence of potentially unwanted programs on their system should run the command line scanner with the /PROGRAM switch.
Please note that VirusScan 7, and higher, has an option that enables users to detect this kind of program automatically (see below).

Aliases

Aliases

  • Keylog-Gopace (Mcafee)
  • Trj/Downloader.AV (Panda)
  • Trojan.Win32.Gopace (AVP)