Selected viruses, spyware, and other threats: sorted alphabetically
Short descriptionWin32/TrojanDropper.VB.NPT is a trojan which tries to download other malware from the Internet. The file is run-time compressed using UPX.
InstallationWhen executed, the trojan copies itself into the following location:
In order to be executed on every system start, the trojan sets the following Registry entry:
"RunmeAtStartup" = "C:WINDOWSsystem32%filename%.exe"
- %temp%svchost.exe (55577 B, Win32/AntiAV.NGX)
Other informationThe trojan quits immediately if it detects a running process containing one of the following strings in its name:
It tries to download several files from the addresses.
These are stored in the following locations:
The HTTP protocol is used. The files are then executed.
The trojan may create the following files: