The Trojan injects its code into the explorer.exe process. This will download files from the following links:
http://www.spamcatchero.biz/*****/bot.dll http://iframebiz.com/exe.php?*****These files will be saved to the Windows system and temporary directories respectively:
%System%\advvpi32.dll %Temp%\If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
- Use Task
Manager to terminate the malicious program
This Trojan opens a range of web pages without the knowledge or consent of the user. It is a Windows PE EXE file. It is 5120 bytes in size. It is packed using FSG. The unpacked file is approximately 23KB in size.
InstallationThe Trojan adds a rule to the Windows Firewall which permits any network activity caused by the Trojan.
Payload

Subscribe
Hot Articles