









 |
W32/Botol.C Trojan
| Name |
W32/Botol.C Trojan |
| Aliases |
Trojan.DL.Agent.DQD, Trojan-Downloader.Win32.Botol.c, Trojan.Gobrena.B |
| Updated on |
June 27, 2009 |
Virus Information - W32/Botol.C Trojan:
W32/Botol.C is a trojan. The trojan will infect Windows systems.
Upon execution, the trojan drops the following files in root of windows installed drive:
ntldr2.exe
ntldr3.exe
ntldr4.exe
winstall.exe
It also drops the following files:
nsProcess.dll in Documents and Settings\Default User\Local Settings\Temp folder.
Update.exe in Program Files\Common Files folder.
services.dll in Program Files\Common Files folder.
MyToolBar.dll in Program Files\ToolBar888 folder.
Activate.exe in Program Files\ToolBar888 folder.
Uninst.exe in Program Files\ToolBar888 folder.
The trojan modifies registry at the following locations:
HKEY_USER\S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXX-XXXX\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_USER\S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXX-XXXX\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall

|