TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
TROJ_REVOP.A
Overview

Malware type: Trojan

Aliases: Trojan-Downloader.Win32.VB.aa (Kaspersky), AdClicker-O (McAfee), Adware.Winpup (Symantec), TR/Dldr.VB.AA.19 (Avira),

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 95, 98, ME, NT, 2000, XP

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

Medium

Distribution potential:

Low

Description: 

This memory-resident Trojan usually arrives downloaded by a component file or by the malware VBS_INOR.M from certain Web sites.

It uploads the following files in the Program Files folder:

  • PUP.EXE
  • OVER.EXE

It also drops a copy of itself using a random file name in the Windows system folder and the file PUP.EXE in the Windows folder. It then modifies the registry to automatically start with Windows.

This Aspack-compressed malware runs on Windows 95, 98, ME, NT, 2000, and XP. It requires certain library files to execute properly.

For additional information about this threat, see:
Solution
Technical Details

Description created: Jan. 8, 2004 2:35:27 PM GMT -0800
Description updated: Sep. 25, 2004 9:58:36 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.