Home Malware Programs Trojans Trojan-Spy.Win32.VB.cfj

Trojan-Spy.Win32.VB.cfj

Posted: July 19, 2011

Trojan-Spy.Win32.VB.cfj is a keylogger that steals every bit of information that passes through your keyboard and to your computer, thereafter sending the data to remote criminals. Like many other kinds of spyware, Trojan-Spy.Win32.VB.cfj will launch itself without your consent and remain active while trying to hide itself from your attention. Trojan-Spy.Win32.VB.cfj has been known to imitate Windows components and any Trojan-Spy.Win32.VB.cfj removal process should use anti-virus program to reduce the chance of accidentally harming your operating system.

The Lengths to Which Trojan-Spy.Win32.VB.cfj Will Go to Spy on Your Typing

Trojan-Spy.Win32.VB.cfj infections can be caused by visiting suspicious websites, downloading fake updates or installing P2P-distributed software. Update your anti-virus software for all recent threats, since Trojan-Spy.Win32.VB.cfj was first seen in July of 2011 and may avoid being noticed by outdated security software. Trojan-Spy.Win32.VB.cfj has been seen originating from both Germany and Russia, and avoiding contact with file sources from those countries may help you avoid being attacked by Trojan-Spy.Win32.VB.cfj.

Like almost every other example of Trojans and spyware in existence, Trojan-Spy.Win32.VB.cfj runs without your permission by adding a startup entry into the Windows Registry, along with other changes. Undoing these changes without assistance from an anti-virus program or from a PC security expert is strongly discouraged and may harm your computer.

Trojan-Spy.Win32.VB.cfj uses a variety of .ini, .dll and .exe files to install itself and remain active. Although you may be able to notice these files, since many of them aren't concealed by rootkit techniques or other methods, removing them by yourself isn't advisable. If you delete Trojan-Spy.Win32.VB.cfj's files without removing related Registry changes, you can damage Windows. Trojan-Spy.Win32.VB.cfj will even have an uninstall.exe file that may confuse you into thinking that Trojan-Spy.Win32.VB.cfj is a legitimate program.

Trojan-Spy.Win32.VB.cfj also uses files that strongly resemble the natural Windows component svchost.exe, although with slight naming variations. Be especially attentive to any files that resemble svchost.exe, but run from the wrong location or use one of Trojan-Spy.Win32.VB.cfj's variant names, like scvhost.exe.

The Proof of Trojan-Spy.Win32.VB.cfj's Illegitimacy

Even though Trojan-Spy.Win32.VB.cfj uses a file structure that resembles that of a normal program, Trojan-Spy.Win32.VB.cfj's main function is highly destructive to your PC and to your privacy. Trojan-Spy.Win32.VB.cfj will use keylogging functions to record all keyboard input for the purpose of stealing passwords, credit card numbers and other private information. After grabbing this data, Trojan-Spy.Win32.VB.cfj will record it into a log file, which it then sends out to criminals.

You may be able to detect Trojan-Spy.Win32.VB.cfj's behavior by looking for opened network ports, firewall issues or inexplicable network activity. The presence of Trojan-Spy.Win32.VB.cfj's memory processes in the Task Manager or poor keyboard responsiveness are also potential keylogger symptoms.

As a direct attack on your privacy that aids other criminals, Trojan-Spy.Win32.VB.cfj should be deleted without a wasted moment. Safe Mode and the use of anti-virus software can be used in conjunction to remove Trojan-Spy.Win32.VB.cfj without even the slightest traces being left behind.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Company\Microsoft\Uninstall.exe
    2 %ProgramFiles%\Company\Microsoft\Uninstall.ini
    3 %System%\scvhost.exe
    4 %System%\sleep.exe
    5 %System%\system.bat
    6 %System%\Teamviewer_Resource_en.dll
    7 %System%\ts.dll
    8 %System%\tv.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}DisplayIcon = "%ProgramFiles%\Company\Microsoft\Uninstall.exe"DisplayName = "Microsoft 1.00"NoModify = 0x00000001NoRepair = 0x00000001UninstallString = "%ProgramFiles%\Company\Microsoft\Uninstall.exe"HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Microsoft 1.00]
Loading...