Threat Database Trojans Downloader.Jadelile

Downloader.Jadelile

By GoldSparrow in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 8
First Seen: May 23, 2012
Last Seen: September 27, 2019
OS(es) Affected: Windows

Downloader.Jadelile is a Trojan that drops malevolent browser plugins to change genuine advertisements. Downloader.Jadelile also add posts on the Facebook wall, which carry web-links to infected web pages. When run, Downloader.Jadelile creates particular infectious files. Downloader.Jadelile also modifies the Windows Registry by creating registry entries. Downloader.Jadelile installs browser plugins for the web browsers such as Internet Explorer, Firefox and Chrome. Downloader.Jadelile creates a directory in %ProgramFiles% to collect Browser Helper Object (BHO) executable files. Downloader.Jadelile then uses browser plugin frameworks to generate software programs to change advertisements illustrated in web browsers.

Aliases

2 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Ikarus Trojan-Downloader.Win32.LilyJade
Kaspersky Trojan-Downloader.Win32.LilyJade.a

SpyHunter Detects & Remove Downloader.Jadelile

File System Details

Downloader.Jadelile may create the following file(s):
# File Name MD5 Detections
1. I Want This.dll b88d4c1b85c75084a341c45548864409 5
2. %ProgramFiles% \[APPLICATION NAME]\[APPLICATION NAME].exe
3. %ProgramFiles% \[APPLICATION NAME]\[APPLICATION NAME].dll
4. %ProgramFiles% \[APPLICATION NAME]\[APPLICATION NAME].ico
5. flashupdate.exe d704b90b505e4a6311d8f1c301137bf3 0
6. I Want This_2514.dll d02664f1e571fbefcc6eca36c4030cef 0
7. SavingsApp.exe e5a8b30cbf59b530db43abc4c3fb8c67 0
8. file.dll 7ce51e541b1a49fde287c8d29f61aa80 0

Registry Details

Downloader.Jadelile may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\[APPLICATION NAME]\Plugins\[RANDOM NUMBERS]\"JavaScript" = "[JAVASCRIPT]"
HKEY_CURRENT_USER\Software\[APPLICATION NAME]\Plugins\[RANDOM NUMBERS]\"Name" = "FacebookFFIE"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\[APPLICATION NAME]\"Publisher" = "[RANDOM CHARACTERS]"

Trending

Most Viewed

Loading...