Content

Generic Dropper.p!A9C72DF4

Type
Trojan
SubType
-
Discovery Date
10/13/2008
Length
19976
Minimum DAT
5404 (10/13/2008)
Updated DAT
5404 (10/13/2008)
Minimum Engine
5.3.00
Description Added
10/13/2008
Description Modified
10/13/2008 11:32 PM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

File PropertyProperty Value
FileName1_1_~1.exe
McAfee DetectionGeneric Dropper.p
Length19,976 bytes
CRCA9C72DF4
MD5623BBA882843A6DAC3E7F6FBDE3F5D97
SHA1DF1AFA7E68DA39CBD51FD8FC6E9F5C1352A0BDA4

Other Common Detection Aliases

Company NameDetection Name
ahnlabWin-Trojan/MalPacked.Gen
AVG (GriSoft)Win32/PEMask
AviraTR/Crypt.XPACK.Gen
BitDefenderTrojan.Dropper.SFU
Dr.WebMULDROP.Trojan
eSafe (Alladin)Suspicious file
Eseta variant of Win32/Delf.NNM
F-ProtW32/Heuristic-KPP!Eldorado
KasperskyTrojan-Spy.Win32.Delf.eld
microsoftTrojan:Win32/Anomaly.gen!B
normanW32/Packed_NsPack.I
risingPacker.Win32.PePatch.d
SophosMal/Emogen-Y
SymantecPacked.Generic.93
Trend MicroPAK_Generic.005
V-BusterPacked/NSPack

Avert® Labs has observed the following system activities:

ActivityRisk Level
Modifies memory of other processes
Critical
Enumerates open windows
Medium
Enumerates running processes
Medium
Writes executable in the windows folder
Low

Other detections that have been observed.

FileNameMcAfee Supported
%WINDIR%\system32\btpanuits.dll
Generic.dx

System Changes

These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files

The following files have been added to the system:

  • %WINDIR%\system32\btpanuits.dll
  • Symptoms

    This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.

    Method of Infection

    Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.

    Removal

    AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.

    Additional Windows ME/XP removal considerations

    Variants

    Variants

      N/A

    All Information

    Overview -

    This is a Trojan detection. Unlike viruses, Trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include e-mail, malicious or hacked Web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.

    Characteristics

    Characteristics -

    File PropertyProperty Value
    FileName1_1_~1.exe
    McAfee DetectionGeneric Dropper.p
    Length19,976 bytes
    CRCA9C72DF4
    MD5623BBA882843A6DAC3E7F6FBDE3F5D97
    SHA1DF1AFA7E68DA39CBD51FD8FC6E9F5C1352A0BDA4

    Other Common Detection Aliases

    Company NameDetection Name
    ahnlabWin-Trojan/MalPacked.Gen
    AVG (GriSoft)Win32/PEMask
    AviraTR/Crypt.XPACK.Gen
    BitDefenderTrojan.Dropper.SFU
    Dr.WebMULDROP.Trojan
    eSafe (Alladin)Suspicious file
    Eseta variant of Win32/Delf.NNM
    F-ProtW32/Heuristic-KPP!Eldorado
    KasperskyTrojan-Spy.Win32.Delf.eld
    microsoftTrojan:Win32/Anomaly.gen!B
    normanW32/Packed_NsPack.I
    risingPacker.Win32.PePatch.d
    SophosMal/Emogen-Y
    SymantecPacked.Generic.93
    Trend MicroPAK_Generic.005
    V-BusterPacked/NSPack

    Avert® Labs has observed the following system activities:

    ActivityRisk Level
    Modifies memory of other processes
    Critical
    Enumerates open windows
    Medium
    Enumerates running processes
    Medium
    Writes executable in the windows folder
    Low

    Other detections that have been observed.

    FileNameMcAfee Supported
    %WINDIR%\system32\btpanuits.dll
    Generic.dx

    System Changes

    These are general defaults for typical path variables. (Although they may differ, these examples are common.):
    %WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
    %SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
    %ProgramFiles% = \Program Files

    The following files have been added to the system:

  • %WINDIR%\system32\btpanuits.dll
  • Symptoms

    Symptoms -

    This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.

    Method of Infection

    Method of Infection -

    Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.

    Removal -

    Removal -

    AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.

    Additional Windows ME/XP removal considerations

    Variants

    Variants -

      N/A