Threat Database Trojans Trojan.Gapz

Trojan.Gapz

By GoldSparrow in Trojans

Trojan.Gapz is a Trojan that opens a back door on the compromised PC. Trojan.Gapz may also drop and install other malware infections.

While being run, Trojan.Gapz embeds itself into the legal process 'explorer.exe'. Trojan.Gapz then ends the genuine process and deletes itself from the file system. Trojan.Gapz uses bootkit functionality to corrupt Master boot and Volume boot records so that it can load automatically whenever you boot up Windows. Trojan.Gapz uses the corrupted boot record to load a malevolent driver code, which permits other components to be downloaded and code to be added into the PC user's processes. Trojan.Gapz may connect to certain remote locations. Trojan.Gapz strives to increase its execution privileges by exploiting one of the following vulnerabilities:Microsoft Windows User Access Control (UAC) Bypass Local Privilege Escalation Vulnerability (CVE-2010-4398)
Microsoft Windows 'Win32k.sys' TrueType Font Handling Remote Code Execution Vulnerability (CVE-2011-3402)
Microsoft Windows AFD Driver CVE-2011-2005 Local Privilege Escalation Vulnerability (CVE-2011-2005)

SpyHunter Detects & Remove Trojan.Gapz

File System Details

Trojan.Gapz may create the following file(s):
# File Name MD5 Detections
1. 2_xxx-porn-movie.avi.exe e5b9295e0b147501f47e2fcba93deb6c 0
2. 757c08c8fb90f6eba505fb6da2081541030ac735 766b7c42d3b6090f5047e4cb56199daa 0

Trending

Most Viewed

Loading...