Installation Trojan:Win32/Wysotot.gen!A is usually installed on the user's PC by software bundlers that advertise free software or games. One installer that we have seen distribute Win32/Wysotot.gen!A is shown below: When the installer is launched, it creates a folder in %ProgramFiles% directory and drops a file there, for example %ProgramFiles%\v9Soft\v9kb.exe. It also drops and launches a DLL in the %TEMP% directory, for example %TEMP%\v9Loader.dll, and installs it as a browser helper object. Payload Changes browser settings
| Attributes | Values |
|---|---|
| rdf:type | |
| rdfs:label |
|
| rdfs:comment |
|
| dcterms:subject | |
| dbkwik:malware/pro...iPageUsesTemplate | |
| Date |
|
| Origin |
|
| Platform |
|
| Name |
|
| Type |
|
| pl |
|
| filetype |
|
| AKA |
|
| Family |
|
| Creator |
|
| Size |
|
| abstract |
|