Content

MultiDropper-JL

Type
Trojan
SubType
Dropper
Discovery Date
03/07/2004
Length
Varies
Minimum DAT
4336 (03/10/2004)
Updated DAT
4336 (03/10/2004)
Minimum Engine
5.1.00
Description Added
03/17/2004
Description Modified
03/17/2004 7:47 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This detection is for a trojan designed to drop and execute other files on the victim machine. The exact filesize, filename will vary according to how the dropper is configured.

When run, the dropper simply extracts and runs the file(s) it contains. The dropper itself does not install in any any onto the victim machine. Subsequent system changes (file system, Registry etc) will be due to the dropped files that have been run.

One sample received by AVERT was configured to drop a dialer application, detected as application Dialer-RAS.as. The dropper was circulated as:

  • SVSHOST.EXE (23,816 bytes)

The file is packed with UPX.

Symptoms

There are no symptoms attributable to the dropper itself. It serves merely to drop and execute other file(s). System changes will be due to the activity of such dropped files.

Method of Infection

This MultiDropper trojan serves only to drop and execute other files on the target system. It does not self-replicate. Likely distribution channels for this trojan include via IRC, via peer-to-peer file-sharing networks, as an attachment in newsgroup postings or email, etc. The file is likely to be named in order to entice the victim to run it.

Trojans may also be received as a result of poor security practices (weak username/password combination on open shares, lack of/or misconfigured firewall protection), or unpatched and vulnerable systems. .

Removal

All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

This is a trojan detection. Unlike viruses, trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.

Characteristics

Characteristics -

This detection is for a trojan designed to drop and execute other files on the victim machine. The exact filesize, filename will vary according to how the dropper is configured.

When run, the dropper simply extracts and runs the file(s) it contains. The dropper itself does not install in any any onto the victim machine. Subsequent system changes (file system, Registry etc) will be due to the dropped files that have been run.

One sample received by AVERT was configured to drop a dialer application, detected as application Dialer-RAS.as. The dropper was circulated as:

  • SVSHOST.EXE (23,816 bytes)

The file is packed with UPX.

Symptoms

Symptoms -

There are no symptoms attributable to the dropper itself. It serves merely to drop and execute other file(s). System changes will be due to the activity of such dropped files.

Method of Infection

Method of Infection -

This MultiDropper trojan serves only to drop and execute other files on the target system. It does not self-replicate. Likely distribution channels for this trojan include via IRC, via peer-to-peer file-sharing networks, as an attachment in newsgroup postings or email, etc. The file is likely to be named in order to entice the victim to run it.

Trojans may also be received as a result of poor security practices (weak username/password combination on open shares, lack of/or misconfigured firewall protection), or unpatched and vulnerable systems. .

Removal -

Removal -

All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A