Win32/Injected [Threat Name] go to Threat

Win32/Injected.F [Threat Variant Name]

Category trojan
Size 579316 B
Aliases Win32:Dropper-gen (Avast)
  InstallCore.LA.adware (AVG)
Short description

Win32/Injected.F is a trojan which tries to download other malware from the Internet. The file is run-time compressed using Inno Setup .

Installation

The trojan is often included in the installation packages of programs downloaded from untrustworthy sources.


The trojan does not create any copies of itself.

Information stealing

Win32/Injected.F is a trojan that steals sensitive information.


The trojan collects the following information:

  • operating system version
  • Internet Explorer version
  • language settings

The trojan attempts to send gathered information to a remote machine.

Other information

The trojan acquires data and commands from a remote computer or the Internet.


The trojan contains a URL address.


It tries to download a file from the address. The HTTP protocol is used.


The file is stored into the following folder:

  • %temp%

The file is then executed.


The file name may vary depending on the current settings stored in the malware executable.


The trojan displays the following dialog boxes:

Please enable Javascript to ensure correct displaying of this content and refresh this page.