Threat Encyclopedia

Selected viruses, spyware, and other threats: sorted alphabetically

Installation

When executed, the trojan copies itself in the following locations:

c:\windows\system32\mslogon.exe
%userprofile%\Start Menu\Programs\Startup\systemnt.exe

This causes the trojan to be executed on every system start.

Spreading

The trojan copies itself in root folders of removable drives using the following filename:

Toy.exe

The following file is created in the same folders:

AutoRun.inf

This causes the trojan to be executed when an infected media is inserted.

Other information

The trojan may display the following messages:

PS: can you find the program's interface ?
History Must Be Remeber !
God said: Let there be light. And there was light.
And darkness was upon the face of the deep.
And the earth was without form, and void.
In the beginning God created the heaven and the earth.
In Memory Of C8C

The trojan contains the following strings:

USB TOY 2.0
This program is not a virus , just a Microphone for me ...