Other versions: .ap, .ci, .cr, .cu, .cv, .dr, .du, .ee, .ef, .eh, .ei, .f, .fc, .gr, .gz, .hp, .hq, .ii, .ij, .ik, .im, .io, .ip, .iq, .jk, .js, .jt, .ju
| Detection added |
Sep 14 2007 12:50 GMT |
| Description added |
Nov 30 2007 |
| Behavior |
TrojanDownloader |
This Trojan downloads other files via the Internet and launches them for execution
on the victim machine without the user’s knowledge or consent. It is
an HTML page which contains Visual Basic Script and Java Script scenarios.
It is 3106 bytes in size.
Once launched, the Trojan decrypts itself and injects its code into the memory
of the process which has the following mutex in the system registry:
{BD96C556-65A3-11D0-983A-00C04FC29E36}
The Trojan exploits a vulnerability in the ActiveX XMLHTTP component to download
a file from the following URL:
http://down.*****88.cn/gaogao.exe
At the moment of writing, this link was not working.
The Trojan exploits a vulnerability in the “ADODB.Stream” ActiveX
component to save the file to the current user’s Windows temporary directory
as “gaogao.exe”:
%Temp%\gaogao.exe
The Trojan then creates a file called "gaogao.vbs" in the current user's temporary
directory:
%Temp%\gaogao.vbs
The Trojan writes code to launch "%Temp%\gaogao.exe" to this file, which is
123 bytes in size.
"%Temp%\gaogao.vbs" will then be launched for execution.
If your computer does not have an up-to-date antivirus, or does not have an
antivirus solution at all, follow the instructions below to delete the malicious
program:
- Delete the original Trojan file (the location will depend on
how the program originally penetrated the victim machine).
- Delete the following files:
%Temp%\gaogao.exe
%Temp%\gaogao.vbs
- Delete all files from %Temporary Internet Files%.
- Disable the vulnerable ActiveX object (see How
to stop an ActiveX control from running in Internet Explorer
- Update your antivirus databases and perform a full scan of the
computer (download a trial version of Kaspersky Anti-Virus).