Date Discovered: 3/7/2004
Date Added: 3/17/2004
This detection is for a trojan designed to drop and execute other files on the victim machine. The exact filesize, filename will vary according to how the dropper is configured.
When run, the dropper simply extracts and runs the file(s) it contains. The dropper itself does not install in any any onto the victim machine. Subsequent system changes (file system, Registry etc) will be due to the dropped files that have been run.
One sample received by AVERT was configured to drop a dialer application, detected as application Dialer-RAS.as. The dropper was circulated as:
SVSHOST.EXE (23,816 bytes)
The file is packed with UPX.
Pint-size luxury and funky style
Shopping for a new car this weekend? See how the BMW X2 stacks up against the Volvo XC40 in our side-by-side comparison.