All Threats

Viruses

Hackers

Spam

Whole site    Viruses
  
Virus Encyclopedia
Riskware
Alerts
Analysis
News
Glossary
Weblog



 
Malware Description Search

 

  Home / Viruses / Virus Encyclopedia / Malware Descriptions / Trojan Programs / Trojan Downloaders

Trojan-Downloader.VBS.Psyme.ir

Other versions: .ap, .ci, .cr, .cu, .cv, .dr, .du, .ee, .ef, .eh, .ei, .f, .fc, .gr, .gz, .hp, .hq, .ii, .ij, .ik, .im, .io, .ip, .iq, .jk, .js, .jt, .ju

Detection added Sep 14 2007 12:50 GMT
Description added Nov 30 2007
Behavior TrojanDownloader

Technical details

This Trojan downloads other files via the Internet and launches them for execution on the victim machine without the user’s knowledge or consent. It is an HTML page which contains Visual Basic Script and Java Script scenarios. It is 3106 bytes in size.

Payload

Once launched, the Trojan decrypts itself and injects its code into the memory of the process which has the following mutex in the system registry:

{BD96C556-65A3-11D0-983A-00C04FC29E36}

The Trojan exploits a vulnerability in the ActiveX XMLHTTP component to download a file from the following URL:

http://down.*****88.cn/gaogao.exe

At the moment of writing, this link was not working.

The Trojan exploits a vulnerability in the “ADODB.Stream” ActiveX component to save the file to the current user’s Windows temporary directory as “gaogao.exe”:

%Temp%\gaogao.exe

The Trojan then creates a file called "gaogao.vbs" in the current user's temporary directory:

%Temp%\gaogao.vbs

The Trojan writes code to launch "%Temp%\gaogao.exe" to this file, which is 123 bytes in size.

"%Temp%\gaogao.vbs" will then be launched for execution.

Removal instructions

If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:

  1. Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
  2. Delete the following files:
    %Temp%\gaogao.exe
    %Temp%\gaogao.vbs
  3. Delete all files from %Temporary Internet Files%.
  4. Disable the vulnerable ActiveX object (see How to stop an ActiveX control from running in Internet Explorer
  5. Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).
 

Copyright © 1996 - 2010
Kaspersky Lab
Industry-leading Antivirus Software
All rights reserved
 

Email: webmaster@viruslist.com