Installation Trojan:Win32/Wysotot.gen!A is usually installed on the user's PC by software bundlers that advertise free software or games. One installer that we have seen distribute Win32/Wysotot.gen!A is shown below: When the installer is launched, it creates a folder in %ProgramFiles% directory and drops a file there, for example %ProgramFiles%\v9Soft\v9kb.exe. It also drops and launches a DLL in the %TEMP% directory, for example %TEMP%\v9Loader.dll, and installs it as a browser helper object. Payload Changes browser settings
Attributes | Values |
---|---|
rdf:type | |
rdfs:label |
|
rdfs:comment |
|
dcterms:subject | |
dbkwik:malware/pro...iPageUsesTemplate | |
Date |
|
Origin |
|
Platform |
|
Name |
|
Type |
|
pl |
|
filetype |
|
AKA |
|
Family |
|
Creator |
|
Size |
|
abstract |
|