W32/Dloader.ACS is a downloader Trojan that will infect Windows systems.

The Trojan arrives on a system as an attachment to email messages spammed by another malware or a malicious user.

Upon execution, the Trojan modifies registry at the following location to load itself during each startup:


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run The Trojan sends HTTP requests to random IP addresses to download and execute files.

More information can be found at this Proland Software page.