Win32/Spy.Odlanor [Threat Name] go to Threat
Win32/Spy.Odlanor.A [Threat Variant Name]
Category | trojan |
Size | 520704 B |
Aliases | Win32:Malware-gen (Avast) |
TR/Spy.Gen (Avira) |
Short description
Win32/Spy.Odlanor.A is a trojan that steals sensitive information. The trojan attempts to send gathered information to a remote machine.
Installation
The trojan does not create any copies of itself.
In order to be executed on every system start, the trojan sets the following Registry entry:
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- "pkrw" = "%malwarefilepath%"
Information stealing
The trojan collects the following information:
- computer name
- user name
- operating system version
- screenshots
The trojan attempts to send gathered information to a remote machine.
Other information
The trojan acquires data and commands from a remote computer or the Internet.
The trojan contains a URL address. The HTTP protocol is used in the communication.
It can execute the following operations:
- download files from a remote computer and/or the Internet
- run executable files
- capture screenshots
- update itself to a newer version
- uninstall itself
- send gathered information