|Detected||Nov 02 2006 17:06 GMT|
|Released||Nov 02 2006 17:06 GMT|
|Published||Jan 11 2007 13:22 GMT|
This Trojan has a malicious payload. It is a Windows PE EXE file. The file is 368 128 bytes in size. áàéò. It is not packed in any way. It is written in Borland Delphi.
Once launched, the Trojan will delete autoexec.bat from the C: root directory:
The Trojan will then attempt to delete explorer.exe from the Windows directory:
This type of behaviour covers malicious programs that delete, block, modify, or copy data, disrupt computer or network performance, but which cannot be classified under any of the behaviours identified above.
This classification also covers “multipurpose” Trojan programs, i.e. those that are capable of conducting several actions at once and which demonstrate several Trojan behaviours in a single program. This means they cannot be indisputably classified as having any single behaviour.