Threat Database Trojans TrojanDownloader:Win32/Vundo.J

TrojanDownloader:Win32/Vundo.J

By Domesticus in Trojans

TrojanDownloader:Win32/Vundo.J is a Trojan downloader that may drop and execute arbitrary files on the compromised PC.

TrojanDownloader:Win32/Vundo.J comes from the Win32/Vundo family, a multiple-component family of applications that display 'out of context' pop-up advertisements. When installed on the affected PC, TrojanDownloader:Win32/Vundo.J makes system changes by adding registry entries and malevolent files. TrojanDownloader:Win32/Vundo.J enters the victimized computer with an icon and version information that varies between samples, which is an executable file with a random name. TrojanDownloader:Win32/Vundo.J is initiated for the first time when the executable file is opened or run. To install itself on the corrupted PC, TrojanDownloader:Win32/Vundo.J uses the certain version information, which will appear in Windows Explorer in the Tiles view. TrojanDownloader:Win32/Vundo.J may use the names, such as Symantec Shared Component, ESET Smart Security and Borland Remote Debugging Server as a form of social engineering to force the victim to open or run the .exe file. TrojanDownloader:Win32/Vundo.J uses the specific icons which have been copied by attackers from genuine software.

File System Details

TrojanDownloader:Win32/Vundo.J may create the following file(s):
# File Name Detections
1. A0052127.exe
2. TXT.exe
3. Dc13.exe

Registry Details

TrojanDownloader:Win32/Vundo.J may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows = "AppInit_DLLs" = "\.dll"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows = "AppInit_DLLs" = "%SystemRoot%\system32\.dll"

Trending

Most Viewed

Loading...