Win32/Crapmisc [Threat Name] go to Threat

Win32/Crapmisc.D [Threat Variant Name]

Category trojan
Size 9216 B
Aliases Trojan-Dropper.Win32.Small.hqq (Kaspersky)
  TrojanDownloader:Win32/Govdi.A (Microsoft)
  Trojan.DownLoader4.54340 (Dr.Web)
Short description

Win32/Crapmisc.D is a trojan which tries to download other malware from the Internet.

Installation

The trojan does not create any copies of itself.


In order to be executed on system start, the trojan sets the following Registry entry:

  • [HKEY_CURRENT_USER\­Software\­Microsoft\­Windows\­CurrentVersion\­Run]
    • "%variable%" = "%malwarefilepath%"

A string with variable content is used instead of %variable% .

Other information

The trojan acquires data and commands from a remote computer or the Internet.


The trojan contains an URL address. The HTTP protocol is used.


It can execute the following operations:

  • download files from a remote computer and/or the Internet
  • run executable files

Please enable Javascript to ensure correct displaying of this content and refresh this page.