Cardown.B is a Java applet based trojan that downloads and
installs Startpage.Y trojan on the system.
Cardown activates when user views a web page or HTML
email that contains reference to the trojan file.
Cardown does not replicate and does not infect the host system,
the only operations it does is to modify Interner Explorer
start page and download and install Startpage.Y trojan component.
Disinfection
Disinfection
Update you Internet Explorer using Windows update
to prevent any further infections.
The Cardown.B is activated when a web site containing the
trojan is loaded with unpacthed Microsoft Internet Explorer
browser. When the JAR file containing the trojan is executed
it uses Microsoft Internet Explorer VerifierBug vulnerability to get
full privileges by escaping the Java security, and execute its
code.
When executed the trojan modifies the Internet Explorer start page
to point to the site where the trojan is downloaded from.
In addition to changing the Internet Explorer settings the trojan
downloads trojan downloader win32.StartPage.Y and executes it.