Fighting Spyware, Malware and Adware one File at a Time.
Navigation Links

Database of Spyware Home

About the Project

View the Database

Forums

Database of Spyware Site Map

Terms of Use

VBS Webdownloader (b)

Overview

Vendor Description

 By visiting a prepared webpage a HTA application is run on the client machine. The Visual Basic script (TrojanDownloader.VBS.Iwill.b) embedded in the HTA application will download a file named "S.EXE". S.EXE (size 1.199 bytes)(Not detected by AVP on september 18, 2003) will download and execute following server: c:\WINDOWS\TEMP\MSCONFIG.EXE (OptixLite 5.0 server aka Backdoor.Delf.em)

Alias

 TrojanDownloader.VBS.Iwill.b,

Category

 Downloader: A program designed to retrieve and install additional files, when run. Most will be configured to retrieve from a designated web or FTP site.

 

Origins

 

Date of Origin

 September, 2003
 

Detection and Removal

Manual Removal

 Follow these steps to remove VBS Webdownloader (b) from your machine. Begin by backing up your registry and your system, and/or setting a Restore Point, to prevent trouble if you make a mistake.

 


 
VBSShaz.A  VBSStress  VBSVBSVG1_5_based!Worm  VBSVBSWG.X!Worm  VBSVBSWG.X.Worm  VBSWebdownloader(b)  VBSWormCreator  VBSWormCreator0.01  VBSWormCreator0.8  VBSWormCreator0.9  
 
Site Map 2006 © Copyright DatabaseofSpyware.com. All rights reserved. Terms of Use
Another Proud Thor Schrock Development