W32/Dloader.ACS is a downloader Trojan that will infect Windows systems.
The Trojan arrives on a system as an attachment to email messages spammed by another malware or a malicious user.
Upon execution, the Trojan modifies registry at the following location to load itself during each startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run The Trojan sends HTTP requests to random IP addresses to download and execute files.
More information can be found at this Proland Software page.
Loading Comments...