Home Malware Programs Trojans TrojanClicker.Win32.VB.ij

TrojanClicker.Win32.VB.ij

Posted: May 24, 2006

Trojan-Clicker.Win32.VB.ij installs itself in the Registry. Trojan-Clicker.Win32.VB.ij may download malicious files from a remote site and run them on your computer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 jptc.dat
    2 vvnmhti.exe
    3 vvnmhtia.exe
    4 vypcety.exe
    5 vypcetya.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_windows_overlay_HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_windows_overlay_componentnextinstanceHKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_windows_overlay_components\0000\controlHKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_windows_overlay_components\0000\controlactiveserviceHKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_windows_overlay_components\0000classHKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_windows_overlay_components\0000classguidHKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_windows_overlay_components\0000configflagsHKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_windows_overlay_components\0000devicedescHKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_windows_overlay_components\0000legacyHKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_windows_overlay_components\0000serviceHKEY_LOCAL_MACHINE\system\currentcontrolset\services\windowsoverlaycomponentsHKEY_LOCAL_MACHINE\system\currentcontrolset\services\windowsoverlaycomponents\enumHKEY_LOCAL_MACHINE\system\currentcontrolset\services\windowsoverlaycomponents\enum0HKEY_LOCAL_MACHINE\system\currentcontrolset\services\windowsoverlaycomponents\enumcountHKEY_LOCAL_MACHINE\system\currentcontrolset\services\windowsoverlaycomponents\enumnextinstanceHKEY_LOCAL_MACHINE\system\currentcontrolset\services\windowsoverlaycomponents\securityHKEY_LOCAL_MACHINE\system\currentcontrolset\services\windowsoverlaycomponentsdisplaynameHKEY_LOCAL_MACHINE\system\currentcontrolset\services\windowsoverlaycomponentserrorcontrolHKEY_LOCAL_MACHINE\system\currentcontrolset\services\windowsoverlaycomponentsimagepathHKEY_LOCAL_MACHINE\system\currentcontrolset\services\windowsoverlaycomponentsobjectnameHKEY_LOCAL_MACHINE\system\currentcontrolset\services\windowsoverlaycomponentsstartHKEY_LOCAL_MACHINE\system\currentcontrolset\services\windowsoverlaycomponentstypecomponentcomponents\0000
Loading...