x
48h OFFER
If you're already a customer of
our homeusers protection,
renew now with 50% off
RENEW NOW
x
SPECIAL OFFER
If you're already a customer of
our homeusers protection,
renew now with 50% off
RENEW NOW
x
HALLOWEEN OFFER
take advantage of our
terrific discounts
BUY NOW AND GET A 50% OFF
x
CHRISTMAS OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 50% OFF
x
SPECIAL OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 50% OFF
x
BLACKFRIDAY OFFER
Buy the best antivirus
at the best price
TODAY ONLY UP TO 70% OFF
x
CYBERMONDAY OFFER
Buy the best antivirus
at the best price
(Only for homeusers)
TODAY ONLY UP TO 70% OFF
Active Scan. Scan your PC free

Virus Encyclopedia

Welcome to the Virus Encyclopedia of Panda Security.

Downloader.ITW

Threat LevelModerate threatDamageHighDistributionNot widespread

Effects 

Downloader.ITW carries out the following actions:

  • It downloads the Trojan Downloader.IUH to the affected computer from the following website:
    http://www.fastmparch.com.ar
  • It opens the following websites without the user's consent:
    http://freife.com
    http://hiltonpalingerine0.html
    http://hiltonpa
    hilton uncensored0.html
    http://hiltonpa
    videoparis and nicky hilton0.html
    http://www.ebay.es
    http://www.gok
    co.com
    http://www.infi
    yads.com
    http://www.keep-an
    ous.com/nav.html
  • It connects to the following websites:
    - http://hiltonpaorden3.txt, in order to check if it is active or not.
    - http://hiltonpaupdate.txt, which indicates the website from where Trj/Downloader.IUH is downloaded.
    - http://hiltonpadownload.txt, which redirects to the website http://hiltonpalingerine0.html

Infection strategy 

Downloader.ITW creates the file VWMANAGER.EXE in the Windows system directory. This file is a copy of the Trojan.

 

Downloader.ITW creates the following entry in the Windows Registry:

  • HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ Run
    vwmanager = %sysdir%\vwmanager.exe

    where %sysdir% is the Windows system directory.
    By creating this entry, Downloader.ITW ensures that it is run whenever Windows is started.

Means of transmission 

Downloader.ITW does not spread automatically using its own means. It needs an attacking user's intervention in order to reach the affected computer. The means of transmission used include, among others, floppy disks, CD-ROMs, email messages with attached files, Internet downloads, FTP, IRC channels, peer-to-peer (P2P) file sharing networks, etc.

Further Details  

Downloader.ITW is written in the Assembler language compiled with Masm32. This Trojan is 13,824 bytes in size when compressed with PECompact.

ARE YOU FACING ANY PC OR INTERNET RELATED PROBLEMS?
FREE SUPPORT INCLUDED. CALL US 24/7

powered by Anytech365