Win32.Mebroot.J

By LoneStar in Trojans | 57 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
More... More

Win32.Mebroot.J Description

Win32.Mebroot.J is a terrible Trojan which can download and install additional malware threats from the Internet. Win32.Mebroot.J can use a large amount of your system resources to trace your computer activities or display pop-up ads that may notably slow down the infected PC or make it crash randomly. Win32.Mebroot.J allows web attackers to obtain remote access to the compromised machine. Win32.Mebroot.J can gather and transmit your email address book to a predetermined email spammer stealthily without your consent or awareness. To safeguard your machine from harm, eliminate Win32.Mebroot.J as quickly as possible.

Type: Trojans

How Can You Detect Win32.Mebroot.J?

Win32.Mebroot.J Removal Details

Win32.Mebroot.J has typically the following processes in memory:

  • %UserProfile%\Application Data\antispy.exe
  • setupapp7070010000.exe

Win32.Mebroot.J creates the following files in the system:

  • %PROGRAM_FILES%\Win32.Mebroot.J \Win32.Mebroot.J

Win32.Mebroot.J creates the following registry entries:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments ‘SaveZoneInformation’ = ‘1′
  • HKEY_CLASSES_ROOT\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ‘tmp’
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ‘[random string]‘
  • HKEY_LOCAL_MACHINE\Software\ Win32.Mebroot.J
  • HKEY_CLASSES_ROOT\MiniBugTransporter.MiniBugTransporterX.1
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ‘Protection Center’v
  • HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\SimpleShlExt
  • HKEY_CURRENT_USER\Software\Malware Defense
  • HKEY_CLASSES_ROOT\TypeLib\{3C2D2A1E-031F-4397-9614-87C932A848E0}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

Important Article Disclaimer

ESG Support Center

This entry was last updated on 09/21/11 and posted on 09/21/11. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.