Trojan droppers are kicking worm butt

happygeek 0 Tallied Votes 305 Views Share

Kaspersky Lab has of the most prevalent viruses for the end of 2007, and although an email worm retains the top spot the more interesting stuff is happening immediately below it in the rankings of shame.

Specifically, the second, fourth and seventh places which are all occupied by variants of the Trojan-Downloader.Win32.Diehard. The .dc modification of this Trojan dropper only appeared for the very first time on 21st December, yet on some days in December it proved virulent enough to account for some 80% of all the malicious traffic seen in email by Kaspersky users. Droppers are particularly worrying, because these deploy the Trojan components that are required to control computers in order to send spam. Think the Warezov family of worms that were so successful during the course of 2007 and you are not far off the mark. In fact you are bang on it, as the Diehard Trojan does pretty much exactly the same thing.

Of the entire top ten viruses on the list, eight are new entrants. The first time this many newcomers have dominated the list for the longest time. A Kaspersky spokesperson said "these trends threaten to provoke significant changes in mail traffic in the near future. Contrary to predictions, Trojan programs and phishing attacks are ending up near the top of the table more and more frequently. Classic email worms re-enter the rankings, then disappear again, creating a backdrop for the real battle which is taking place. And although these events are not on the same scale or as long lived as epidemics of previous years, they are no less dangerous."

Dani AI

Generated

A brief expert summary anchored to the thread: ’s pointer to the Kaspersky writeup highlights why dropper-based attacks became common. The symptoms reported by —IM/Bittorrent failing to start, files not removable, and the infection returning after reboot—fit a classic dropper/persistence pattern. Ignore unsolicited “registry cleaner” offers like the one posted by ; those are often useless or harmful.

Immediate containment and cleanup checklist:

  • Isolate the machine from the network (unplug Ethernet / disable Wi‑Fi) to stop further payload download and outbound spam.
  • Attempt a clean scan from Safe Mode (F8 -> Safe Mode). If AV or apps are blocked there, use a bootable rescue scanner (offline rescue media) and scan the disk.
  • Look for persistence points with trusted tools (Autoruns or msconfig): check HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HKCU\...Run, the Startup folder, Services, Scheduled Tasks, and any unknown drivers. Remove only clearly malicious entries or quarantine them.
  • Inspect C:\Windows\System32\drivers\etc\hosts and reset networking state (netsh winsock reset) if name resolution or IM clients are blocked.
  • Identify suspicious network activity with netstat -ano and match PIDs with tasklist /FI "PID eq <pid>" to find running backdoors.
  • If removal keeps failing or infection reappears after reboot, back up personal data (scan backups offline), then wipe and reinstall from known-good media. Do not restore system files from an infected image.

Prevention and final notes: change all account passwords only after restoring from a clean system; prioritize patching the OS and apps; deploy reputable endpoint protection and restrict outbound SMTP at the gateway for networks with many endpoints. Registry cleaners and unknown “toolkits” rarely solve malware problems and can make recovery harder.

shootie 0 Newbie Poster

Registry ToolKiT

Increase system speed and stability by removing
corrupted registry files with Registry Toolkit.

It is the safest and easiest way to improve your PC's performance.

Your Computer keeps crashing? Receiving weird error messages? We offer a quick solution to most system errors and increase the performance of your computer in the same time.

Scan your computer to see how many errors are there in your registry.

GET IT TODAY!!!

just2rock 0 Newbie Poster

I have also been Fucked off by this "TROJAN Dropper"...cAnt delete..quarantine...

n most imp. cant load BITTORRENT.exe and GOOGLE TALK,YAHOO Massenger...Use BRAIN DANIWEBians n HELP us all!

just2rock 0 Newbie Poster

I have been attacked by"TROJAN DROPPER".....it stops me opening GTALK,YAHOO MASENGER ,Bittorrent SERVICES...and thus DELETE/QUARATINE them...and reapear on REBOOT again.HELP ME PLZZZZZZZZZ

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.