What is Trojan.Downexec.C

Trojan.Downexec.C is a Trojan horse that may download files and steal information from the compromised computer.

Technical details of W32.Downadup.B

Discovered: December 30, 2008
Updated: December 30, 2008 2:48:09 PM
Type: Trojan, Virus

Characteristics of W32.Downadup.B

When the Trojan Trojan.Downexec.C is executed, it creates the following file:
%Windir%\System32\GameMon.des

Trojan.Downexec.C then modifies the following registry entry, so that it starts when certain programs start:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\”AppInit_DLLs” = “GameMon.des”

Trojan.Downexec.C then attempts to steal information from the PlayOnline Viewer program, sending it to one of the following URLs:[http://]p://chengzhibing.com/xinfff/save[REMOVED][http://]p://452233794.com/cert/save[REMOVED]

Trojan.Downexec.C also periodically scans all removable drives for executable files and attempts to infect them.