Main Menu
Home
Bookmark
Contact Us



 
Downloader.CashToolbar Trojan Downloader Information

Name: Downloader.CashToolbar
Category: Trojan Downloader
Advice: Remove
Risk: High Risk High risk threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction. May open up communication ports, use polymorphic tactics, stealth installations, and/or anti-spy counter measures. May use a security flaw in the operating system to gain access to your computer.
Description:

This detection is for a downloading trojan that serves only to download and execute a remote file.

Once executed, it installs itself on the victim machine using deceptive file and folder names:

c:WINNTsystem32driverscd_load.exe
c:WINNTsystem32inetsrvMSCStat.exe

The following Registry hooks are added:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun "CashToolbar" = C:WINNTsystem32inetsrvMSCStat.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun "ClickTheButton" = C:WINNTsystem32driverscd_load.exe

After a delay, the following fake error message is displayed:

"Windows Error: Windows has detected spyware, click OK to remove."

Upon clicking OK, the trojan attempts to download remote files.

Signatures: process: svchost.exe: MD5 Hash: aeedc5c251b79785ad8... process: svchost.exe: MD5 Hash: e0fa3d9f794aaaa7c8f... process: cd_load.exe: MD5 Hash: b7f400e556e56b04826... process: cd_load.exe: MD5 Hash: 553dd729461cef24bd6... process: cd_load.exe: MD5 Hash: 5fca53ad4a905685db3... process: mscstat.exe: MD5 Hash: df7f8bbb39861572c56..
Type: Trojan Downloader - A Trojan software is any software on a user's computer that the user is not aware or intentionally installed. Most Trojan software is designed to perform some sort of actions that could jeopardize the user's security or privacy.



Top Trojan Downloader Visited Pages:
TrojanDownloader:Win32/Small.ADO - 335 visits
Trojan.Downloader.Slvr - 199 visits
Trojan.Downloader.Small.ADR - Alias: TrojanDownloader:Win32/Small.ADR - 60 visits
Peper - Alias: Backdoor.VB.nb, pepar trojan, Quadro - 54 visits
Bagle.HP - 46 visits
Bagle.BV - 45 visits
Trojan.Downloader.U - 45 visits
Trojan.Dropper.AV - Alias: Troj/Dropper-AV - 43 visits
Trojan.Downloader.Small.HS - Alias: TrojanDownloader:Win32/Small.HS - 40 visits
eXact.Downloader - 40 visits

Random Trojan Downloader Pages:
TrojanDownloader:Win32/Small.AEA
XferPro
CallingHome.biz - Alias: CallingHome, Downloader-KL, Calling Home
Web P2P Installer
Slime.a - Alias: TrojanDownloader.Win32.Slime.a
Downloader.Lunii
TrojanDownloader:Win32/Agent.AG
Trojan.Downloader.Bluestart - Alias: TrojanDownloader:Win32/VB.GA
Smoke Downloader - Alias: Smoke Downloader, TrojanDownloader.Win32.Smokedown.a
Trojan.Downloader.U


 


© 2006-2008 spyware32.com - Privacy Policy