
No surprises here that it�s actually a malicious program, and will drop a file called server.exe into your Application Data folder:

From there, endless calls go out to furz(dot)no-ip(dot)biz, although it�s currently out of action so whatever grand plan the creator had in mind isn�t currently materialising. Of course, the no-ip URL could come back to life at some point so it�s probably best not to get too complacent. VirusTotal detections were showing as 7/41 a day or two ago, but it�s gone up slightly to 13.
We detect this as Trojan.Win32.Generic!BT.
Christopher Boyd
No comments:
Post a Comment