Additional Details
This family of downloaders use XMLHTTP control to download and ADODB.Stream
control to write malware on the vulnearble machine, often combined with some
other vulnerabilty that allows the downloader to escape from the Internet
Explorer internet zone.
Typically SillyDownloader replaces the Windows Media Player in order to make
sure that the downloaded component gets executed.
The downloaded component usually contains an another trojan or a backdoor.
Further information about ADODB control is available from Microsoft at:
http://support.microsoft.com/?kbid=870669
Write-up:
Sami Rautiainen, July 13th, 2005;