This description is for a Downloader Trojan, which when executed, could further download more malicious components from the web and install them on the victims machine.
The characteristics of this downloader in regards to file names, URLs accessed, files downloaded etc. will differ, depending the way in which the attacker had configured it. Hence, this is a general description.
When executed, this malware creates the following files:
The malware also drops copies of itself in any inserted usb disk, along with several .lnk files pointing to this executable. Existing folders are randomly selected and made hidden, with .lnk files created with folder icons to mimick existing folders.
The malware then creates the following registry entries:
The above registry entry ensures that the malware executes on Windows Startup.
The above registry entry ensures that the hidden files and folders and not displayed in Windows Explorer.
Connections may be made on the following ports*:
*Other port communication may also be possible with newer variants.
The malware attempts to connect to the following URLs to download additional malware:
This malware spreads by copying itself to network shares and to removable devices, along with an Autorun.inf.
Infection starts either with manual execution of the infected file or by simply navigating to the folders containing the infected files, whereby the Autorun.inf file could cause automatic execution of the worm.
This malware may also be recieved under the premise that it is beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).