Threat Database Trojans Trojan.VB.gip

Trojan.VB.gip

By Sumo3000 in Trojans

Trojan.VB.gip is Trojan infection. This computer threat is used to harvest confidential information from compromised computers and then send the stolen information to a remote hacker. Trojan.VB.gip often spreads as an attachment in spammed e-mails. The attachment is an executable that automatically runs and installs Trojan.VB.gip onto your PC once clicked on. On successful installation, Trojan.VB.gip will lower the security settings and give a remote hacker access to the system. Trojan.VB.gip may also modify the browser settings and redirect a victim to malicious or advertising websites.

File System Details

Trojan.VB.gip may create the following file(s):
# File Name Detections
1. %SYSTEMROOT%\system32\prun.exe

Registry Details

Trojan.VB.gip may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{46C82107-C059-4B5A-8BEE-361B06DB044C}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{6742CC3A-65E8-4ED9-B051-AA119195C7BE}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Explorer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{96F7F230-8ADE-4930-A88F-3547C6A30BFF}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{98A60C8C-2568-4029-9FB2-F2ED7E2DA8E8}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ System File
MICROSOFT\WINDOWS\CURRENTVERSION\RUN\prunnet
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{7B618C0C-8D13-4F49-8559-BE04DC96899C}
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Athan
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows Log Agen

Trending

Most Viewed

Loading...