Threat Database Trojans TR/DNSChanger.VJ.2

TR/DNSChanger.VJ.2

By Sumo3000 in Trojans

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 13
First Seen: October 18, 2011
Last Seen: April 21, 2022
OS(es) Affected: Windows

TR/DNSChanger.VJ.2 is a self-mutating Trojan which is created to reset DNS settings of the compromised PC. TR/DNSChanger.VJ.2 is able to create and control constant connections to some external servers and might mutate into so-called improved versions while remaining on the affected computer system. TR/DNSChanger.VJ.2 may also drop other malware infections and deliver annoying pop-up ads. TR/DNSChanger.VJ.2 enables cybercriminals to gain remote access to the corrupted PC. Remove TR/DNSChanger.VJ.2 immediately upon detection.

File System Details

TR/DNSChanger.VJ.2 may create the following file(s):
# File Name Detections
1. %ProgramFiles%\PopinMV
2. %ProgramFiles%\Gen:Variant.Buzy.4104
3. %ProgramFiles%\PopinMV\PopinMVUpdate

Registry Details

TR/DNSChanger.VJ.2 may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths Path = "%ProgramFiles%\PopinMV\PopinMVUpdate" (Default) = "%ProgramFiles%\PopinMV\PopinMVUpdate\TR/DNSChanger.VJ.2"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run PopinMVUpdate = "%ProgramFiles%\TR/DNSChanger.VJ.2"

Trending

Most Viewed

Loading...