DS Web Downloader


· Overview ·
· Origins ·
· Distribution ·
· Operation ·
· Detection and Removal ·
· Research ·



Overview

Vendor Notes:

From the doc: 'a non backdoored web downloader unlike FC's, this comes with the following 1. Melt server - the server deletes it self after the download is completed, removing its tracks. 2. ICQ Notify - the server notifys you if the download completed succesfully or for some reason an error occured. 3. This web downloader uses the wininet functions to download the file, not what some of the other ones available use, the URLDownloadToFile in the urlmon library. 4. A very easy to use and fast editor to read and write the server's settings quickly. 5. A small server size, ~3kb, very small compared to others which are over 10kb.'
1.01: From the doc: 'Ability to have ICQ notify or not and ability to use melt server or not. ICQ notify tells the filesize of the downloaded file. Added hide from ctrl+alt+del. A few little things you wont notice.'
2.0: From the doc: 'i have made this version undetected by norton anti virus 2002 with latest definations.'
3.0: From the doc: 'DS WebDL is a simple assembly program when executed, hides from the Windows 9x task manager then waits for a connection to the internet. On connection, the server will begin to download the file you have specified in the editor. If the download is succesful, the server will then attempt to notify you that the file is downloaded and will tell you the operating system they were running after the download completed along with the path and filename of where it was downloaded. After the ICQ notification, it attempts to self delete it self to leave no traces behind to the victim who ran the server.'

Alias:

(TrojanDownloader.Win32.Dsweb.101, Downloader.cfg trojan, Downloader-Z trojan, TrojanDownloader.Win32.Dsweb, TrojanDownloader.Win32.Dsweb.10, TrojanDownloader.Win32.Phostic

Category:

Downloader: A program designed to retrieve and install additional files, when run. Most will be configured to retrieve from a designated web or FTP site.

Variants:

  • DS Web Downloader 1.00
  • DS Web Downloader 1.01
  • DS Web Downloader 2.0
  • DS Web Downloader 3.0
  • Similar Pests:

    Downloader

    Origins

    Author:

    Freedumb,

    By This Author:

    AVKillah · AVKillah 2 · DS Web Downloader 1.00 · DS Web Downloader 1.01 · DS Web Downloader 2.0 · DS Web Downloader 3.0 · Infamy · Whomp · Whomp 1.0 · Whomp 4

    Group:

    TrojCorp Productions

    By This Group:

    DS Web Downloader 1.00 · Phr0stic

    Group:

    TrojCorp Productions

    By This Group:

    DS Web Downloader 1.00 ·

    Date of Origin:

    Variants from December, 2001 to May, 2002

    Distribution

    Prevalence:

  • DS Web Downloader 1.00: 0.1%
  • More Info

    Clot Factor:

  • DS Web Downloader 1.00: < 1
  • The "Clot Factor" is a measure of how much a pest "gums up" a machine by adding registry entries, files, and directories. As more objects are placed in a machine, manual removal becomes more difficult and more error-prone.

    Countries Affected:

    In the past three months, we have received reports of DS Web Downloader in United States.

    Operation

    Storage Required:

  • DS Web Downloader 1.00: at least 729 KB
  • DS Web Downloader 1.01: at least 397 KB
  • DS Web Downloader 2.0: at least 61 KB
  • DS Web Downloader 3.0: at least 49 KB
  • ScreenShot:


    DS Web Downloader 1.0



    DS Web Downloader 1.01



    DS Web Downloader 2.0



    DS Web Downloader 3.0


    Detection and Removal

    Automatic Removal:

    PestPatrol detects this.

    PestPatrol removes this.



    Manual Removal:

    Follow these steps to remove DS Web Downloader from your machine. Begin by backing up your registry and your system, and/or setting a Restore Point, to prevent trouble if you make a mistake.
    Stop Running Processes:

    Kill these running processes with Task Manager:

    Remove Files:

    Remove these files (if present) with Windows Explorer:

    Research

    File Analyses:

    More Info:

  • AllTheWeb, AltaVista, AOL Search, Ask Jeeves, Google, HotBot, Lycos, LookSmart, MSN, Yahoo!
  • Research By:

  • PestPatrol's Pest Research Center
  • Last Revised:

    April 02, 2005