Downloader.Liftoh

By GoldSparrow in Trojan Downloader

Threat Scorecard

Threat Level: 50 % (Medium)
Infected Computers: 100
First Seen: May 10, 2013
Last Seen: February 21, 2023
OS(es) Affected: Windows

Downloader.Liftoh is a Trojan that drops more malware infections onto the compromised PC. Once run, Downloader.Liftoh replicates itself to the specific location. Downloader.Liftoh creates the registry entry so that it can load automatically whenever you start Windows. Downloader.Liftoh encompasses an injected DLL file which is unpacked into memory. The DLL file can drop and run payloads or inject them into current processes. Downloader.Liftoh drops and runs malevolent files from the specific web addresses.

SpyHunter Detects & Remove Downloader.Liftoh

File System Details

Downloader.Liftoh may create the following file(s):
# File Name Detections
1. %UserProfile%\Application Data\[RANDOM LETTERS].exe

Registry Details

Downloader.Liftoh may create the following registry entry or registry entries:
Regexp file mask
%WINDIR%\Temp\Networks\taskmgr.exe
HKEY_CURRENT_USER\Software\[RANDOM LETTERS]\"CurrentPath111" "%WorkingDirectory%\%SampleName%"

Directories

Downloader.Liftoh may create the following directory or directories:

%WINDIR%\dllhost

Trending

Most Viewed

Loading...