Selected viruses, spyware, and other threats: sorted alphabetically
Short description
The trojan tries to download several files from the Internet. The files are then executed. Installation
When executed the trojan copies itself in the following locations: - %system%\reader_s.exe
- %userprofile%\reader_s.exe
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\Run]
"reader_s" = "%system%\reader_s.exe" - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Run]
"reader_s" = "%userprofile%\reader_s.exe"
- svchost.exe
Other information
The trojan contains a list of URLs. It tries to download several files from the addresses. These are stored in the following locations:
- %temp%\BN%variable%.tmp
A string with variable content is used instead of %variable% .
The downloaded files contain encrypted executables. After decryption, the trojan runs these files.
The trojan may create and run a new thread with its own program code within any running process.
