Prevent Online Threats

Downloader.Win32.Harni

Details
Downloader.Win32.Harnig
This Trojan is written in Assembler.
Installation
Harnig copies itself as an .exe file and a .dll file with the same random name in the Windows directory. The .exe version is registered in the system registry auto-run key as:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
The Trojan also creates the following file in the Windows directory:
WININIT.INI
Malicious effects
Harnig downloads Backdoor.Afcore.aa from http//system.hoha.ru/x.pl?10 and launches it. Backdoor.Afcore.aa functions identically to Backdoor.Afcore.q

Related Posts

  • Trojan-Downloader.Win32.Small.ap
  • Trojan-Downloader.Win32.Bagle
  • Trojan-Downloader.Win32.Tibser
  • Trojan-Downloader.Win32.VB.j
  • Trojan-Downloader.Win32.Bagle
  • Leave a Reply


    Spyware Removal Spyware Protection Tools