| Malware name | Script.Dldr.Psyme.GX.3 | | Type | Script | | Affected platform | Win32 | | Media-Type | none | | MD5 checksum | 0315B9848D45DF15E150E7E645FC715A | | Static file | no | | Filesize | 85,613 Bytes | Alias names (also known as) | | Webwasher Proactive | JavaScript.BufferOverflow.gen!High | | Sophos | Exp/MS06055-A | | McAfee | JS/Exploit-BO.gen | | CA ETrust | JS/Veemyfull!exploit |
| | Protection | | Webwasher Proactive | Database Version: 42 |
| | Side effects | - Downloads a malicious file
- Makes use of software vulnerability
| | Propagation | No own spreading routine |
|
Description:
Files
It tries to download a file:
– The location is the following:
• http://v2statscount.net/**********
It is saved on the local hard drive under:
%system drive root% \U.exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too.