Once launched, the Trojan creates the following record in the system registry:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]- Use Task Manager to terminate the Trojan process (the process will have the same name as the Trojan file)
- Delete the original Trojan file (its location will depend on how the Trojan initially penetrated the victim machine).
- Delete the following registry key:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
This primitive Win32 Trojan is designed to falsify the number of hits on www.sex.de. It is written in Assembler and is 3072 bytes in size. It is not packed in any way.
Payload

Subscribe
Hot Articles