Infection Channel: Downloaded from the Internet, Dropped by other malware, Infects files
This malware is responsible for high infection numbers in EMEA, NABU, and China.
To get a one-glance comprehensive view of the behavior of this File infector, refer to the Threat Diagram shown below.

This file infector arrives via removable drives. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It deletes registry entries related to antivirus programs. Doing this allows this malware to execute its routines without being detected by installed antivirus programs. It creates certain registry entries to disable applications related to security.
It infects by appending its code to target host files.
It connects to certain URLs. It may do this to remotely inform a malicious user of its installation. It may also do this to download possibly malicious files onto the computer, which puts the computer at a greater risk of infection by other threats.
Connect with us on
| | | |