When launching, the Trojan terminates processes with names from the list below:
AVPCC.EXE AVKSERV.EXE ECENGINE.EXE FP-WIN.EXE VETTRAY.EXE ACKWIN32.EXE AVNT.EXE ESAFE.EXE FPROT.EXE F-PROT95.EXE IOMON98.EXE AVWIN95.EXE AVE32.EXE ANTI-TROJAN.EXE _AVPCC.EXE APVXDWIN.EXE CLAW95CF.EXE _FINDVIRU.EXE FINDVIRU.EXE NAVNT.EXE VET95.EXE SCAN32.EXE RAV7.EXE NAVAPW32.EXE VSMAIN.EXE GUARDDOG.EXE RULAUNCH.EXE ALOGSERV.EXE OGRC.EXE NAVAPSVC.EXE SMSS.EXE NSPLUGIN.EXE NOD32.EXE _AVPM.EXE AMON.EXE NAVWNT.EXE NAVW32.EXE SPIDER.EXE AVPM.EXE ATGUARD.EXE BLACKICE.EXE LOOKOUT.EXE CMGRDIAN.EXE IAMAPP.EXE OUTPOST.EXE ZONALARM.EXE
The Trojan then ceases running.
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
- Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
- Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).
This Trojan has a malicious payload. It is a Windows PE EXE file. It is packed using UPX. It is written in C . The size of infected files may vary from 6KB to 80KB.
Payload
Subscribe
Hot Articles