This file infector infects by inserting its code to unused space in host files.
File size: Varies
File type: PE
Memory resident: Yes
Initial samples received date: 06 Sep 2010
Payload: Modifies files
Autostart Technique
This file infector drops the following file(s) in the Windows Startup folder to enable its automatic execution at every system startup:
Other System Modifications
This file infector adds the following registry entries as part of its installation routine:
HKEY_CURRENT_USER\Software\Microsoft
Microsoft = 1
File Infection
This file infector infects by inserting its code to unused space in host files.
Other Details
This file infector does the following:
- Infects running processes. Infected files are detected as PE_LICAT.SM
Connect with us on
| | | |