TrojanDownloader:Win32/Vundo.J

By Domesticus in Trojans | 38 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
More... More

TrojanDownloader:Win32/Vundo.J Description

TrojanDownloader:Win32/Vundo.J is a Trojan downloader that may drop and execute arbitrary files on the compromised PC.
TrojanDownloader:Win32/Vundo.J comes from the Win32/Vundo family, a multiple-component family of applications that display ‘out of context’ pop-up advertisements. When installed on the affected PC, TrojanDownloader:Win32/Vundo.J makes system changes by adding registry entries and malevolent files. TrojanDownloader:Win32/Vundo.J enters the victimized computer with an icon and version information that varies between samples, which is an executable file with a random name. TrojanDownloader:Win32/Vundo.J is initiated for the first time when the executable file is opened or run. To install itself on the corrupted PC, TrojanDownloader:Win32/Vundo.J uses the certain version information, which will appear in Windows Explorer in the Tiles view. TrojanDownloader:Win32/Vundo.J may use the names, such as Symantec Shared Component, ESET Smart Security and Borland Remote Debugging Server as a form of social engineering to force the victim to open or run the .exe file. TrojanDownloader:Win32/Vundo.J uses the specific icons which have been copied by attackers from genuine software.

Type: Trojans

How Can You Detect TrojanDownloader:Win32/Vundo.J?

TrojanDownloader:Win32/Vundo.J Removal Details

TrojanDownloader:Win32/Vundo.J has typically the following processes in memory:

  • A0052127.exe
  • TXT.exe
  • Dc13.exe

TrojanDownloader:Win32/Vundo.J creates the following registry entries:

  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows = “AppInit_DLLs” = “\.dll”
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows = “AppInit_DLLs” = “%SystemRoot%\system32\.dll”

Important Article Disclaimer

ESG Support Center

This entry was last updated on 10/26/12 and posted on 10/26/12. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.