Threat Database Trojans Downloader.Generic_c.AHI

Downloader.Generic_c.AHI

By ZulaZuza in Trojans

Downloader.Generic_c.AHI is yet another variant originating from the Generic Downloader family, and should thus be taken very seriously. Downloader.Generic_c.AHI typically spreads via email, malicious or hijacked web pages, Internet Relay Chat (IRC) and peer-to-peer (P2P) networks. Once installed onto a computer, Downloader.Generic_c.AHI retrieves and executes files from a remote server on the compromised machine, which is typically a password-stealing component.

File System Details

Downloader.Generic_c.AHI may create the following file(s):
# File Name Detections
1. %WinDir%\services.exe

Registry Details

Downloader.Generic_c.AHI may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\ Shell= "Explorer.exe %WinDir%\services.exe"

Trending

Most Viewed

Loading...