Main Menu
Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Apa7HY

#1
Hello,

This message has been generated by the automated submission tracking system. If we already detect these files, the message below tells you how we identify this threat. Your submission will be passed to a virus analyst.

lazylaunch.exe - Trojan-Dropper.Win32.Clons.emf

New malicious software was found in this file. The next antivirus database update will include detection for this malware. Thank you for your help.

lazytown.txt

This file is being processed.

Best regards, Kaspersky Lab

10/1, 1st Volokolamsky Proezd, Moscow, 123060, Russia
Tel./Fax: + 7 (495) 797 8700
http://www.kaspersky.com http://www.viruslist.com                                                                                                                                       


Looks like good old lazylaunch.exe leaves a backdoor.  Tell me why it autoruns some script on my machine and tries to gain access to COM Surrogate?  Then later, tries to access SVCHOST?