Home / malwarePDF  

Trojan:JS/Kovter.A


First posted on 10 November 2015.
Source: Microsoft

Aliases :

There are no other names known for Trojan:JS/Kovter.A.

Explanation :

Threat behavior

This threat is a malicious JavaScript used to run Trojan:Win32/Kovter.C.

It is added to autorun registry modifications made by Trojan:Win32/Kovter.C!reg. For example, we have seen this threat used in the following registry modifications:

In subkey: HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Sets value: ""
With data: ""

In subkey: HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Sets value: ""
With data: ""

In subkey: HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Sets value: ""
With data: ""

Symptoms

The following can indicate that you have this threat on your PC:

  • You see these entries or keys in your registry:

    In subkey: HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    Sets value: ""
    With data: ""

    In subkey: HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    Sets value: ""
    With data: ""

    In subkey: HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
    Sets value: ""
    With data: ""

Last update 10 November 2015

 

TOP