This Trojan is a Windows PE EXE file. It is 33 792 bytes in size.
When launched, the Trojan copies its executable file to the Windows root directory:
In order to ensure that the Trojan is launched automatically each time Windows is restarted, it adds a link to its executable file to the system registry:
[HKCUSoftwareMicrosoftWindows NTCurrentVersionWindows] "Run" = "%WinDir%Winrep.exe" [HKCUSoftwareMicrosoftWindows NTCurrentVersionWindows] "load" = "%WinDir%Winrep.exe"
The Trojan also creates the following system registry key parameter:
[HKLMSOFTWAREMicrosoftWindows NTCurrentVersionCompatibility] "COSTARO" = "10.05.2007"
The Trojan also creates the following empty file.
The Trojan will periodically cause the following message to be displayed:
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program: