Content
MultiDropper-JL
- Type
- Trojan
- SubType
- Dropper
- Discovery Date
- 03/07/2004
- Length
- Varies
- Minimum DAT
- 4336 (03/10/2004)
- Updated DAT
- 4336 (03/10/2004)
- Minimum Engine
- 5.1.00
- Description Added
- 03/17/2004
- Description Modified
- 03/17/2004 7:47 AM (PT)
Tab Navigation
Characteristics
This detection is for a trojan designed to drop and execute other files on the victim machine. The exact filesize, filename will vary according to how the dropper is configured.
When run, the dropper simply extracts and runs the file(s) it contains. The dropper itself does not install in any any onto the victim machine. Subsequent system changes (file system, Registry etc) will be due to the dropped files that have been run.
One sample received by AVERT was configured to drop a dialer application, detected as application Dialer-RAS.as. The dropper was circulated as:
- SVSHOST.EXE (23,816 bytes)
The file is packed with UPX.
Symptoms
There are no symptoms attributable to the dropper itself. It serves merely to drop and execute other file(s). System changes will be due to the activity of such dropped files.
Method of Infection
This MultiDropper trojan serves only to drop and execute other files on the target system. It does not self-replicate. Likely distribution channels for this trojan include via IRC, via peer-to-peer file-sharing networks, as an attachment in newsgroup postings or email, etc. The file is likely to be named in order to entice the victim to run it.
Trojans may also be received as a result of poor security practices (weak username/password combination on open shares, lack of/or misconfigured firewall protection), or unpatched and vulnerable systems. .
Removal
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Variants
Variants
N/A
All Information
Overview -
This is a trojan detection. Unlike viruses, trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.
Characteristics
Characteristics -
This detection is for a trojan designed to drop and execute other files on the victim machine. The exact filesize, filename will vary according to how the dropper is configured.
When run, the dropper simply extracts and runs the file(s) it contains. The dropper itself does not install in any any onto the victim machine. Subsequent system changes (file system, Registry etc) will be due to the dropped files that have been run.
One sample received by AVERT was configured to drop a dialer application, detected as application Dialer-RAS.as. The dropper was circulated as:
- SVSHOST.EXE (23,816 bytes)
The file is packed with UPX.
Symptoms
Symptoms -
There are no symptoms attributable to the dropper itself. It serves merely to drop and execute other file(s). System changes will be due to the activity of such dropped files.
Method of Infection
Method of Infection -
This MultiDropper trojan serves only to drop and execute other files on the target system. It does not self-replicate. Likely distribution channels for this trojan include via IRC, via peer-to-peer file-sharing networks, as an attachment in newsgroup postings or email, etc. The file is likely to be named in order to entice the victim to run it.
Trojans may also be received as a result of poor security practices (weak username/password combination on open shares, lack of/or misconfigured firewall protection), or unpatched and vulnerable systems. .
Removal -
Removal -
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A