Home Malware Programs Trojans Troj/JavaDl-NJ

Troj/JavaDl-NJ

Posted: July 11, 2012

Threat Metric

Threat Level: 1/10
Infected PCs: 1,054
First Seen: July 11, 2012
Last Seen: June 20, 2023
OS(es) Affected: Windows

Troj/JavaDl-NJ is a Java-based applet that's used to install one of three types of backdoor Trojans, with the type of Trojan being based on your operating system. Troj/JavaDl-NJ, also known by the alias Trojan-Downloader:Java/GetShell.A, has only been seen in one site that has since been shut down. However, since this site was a benign website that was hacked to include Troj/JavaDl-NJ, rather than an intentional host for Troj/JavaDl-NJ attacks, SpywareRemove.com malware researchers rate the probability of Troj/JavaDl-NJ being inserted into other benevolent websites in the future to be fairly high. Although Troj/JavaDl-NJ's payload is a non-negligible threat to your PC, as long as you're careful enough to refuse the Java prompt for Troj/JavaDl-NJ when it appears, there shouldn't be much chance of Troj/JavaDl-NJ successfully attacking your computer.

Troj/JavaDl-NJ – the Ongoing Corruption of the Web's Safety

Troj/JavaDl-NJ is a Java-based PC threat that's hosted, either deliberately or unintentionally, on various websites. The first, last and only site so far to function for this service is a Columbia transportation company website that was shut down once the security compromise was discovered. Given this chain of events, SpywareRemove.com malware experts emphasize the importance of having updated website maintenance software and other security mechanisms to deal with potential hacker-based intrusions. Careful monitoring of your site's code should also reveal Troj/JavaDl-NJ quickly, and visitors should be able to notice Troj/JavaDl-NJ due to the appearance of an unusual Java prompt.

This prompt requests that you run a vaguely-named Java applet (in fact, its listed name actually is 'Java') by the ComuTV company. If you accept this prompt, Troj/JavaDl-NJ will attempt to detect your operating system as one out of the 'big three' brands: Linux, Mac or Windows. After detecting your OS, Troj/JavaDl-NJ will install one of three Trojans:

  • For Mac computers, OSX/Dloadr-DPG, alias Backdoor:OSX/GetShell.A.
  • For Windows computers, Mal/Krap-D, alias Backdoor:W32/GetShell.A.
  • For Linux computers, Linux/Dldr-GV, alias Backdoor:Linux/GetShell.A.

The Dangers That Await Once You Click That Innocent Prompt from Troj/JavaDl-NJ

Trojans that are installed by Troj/JavaDl-NJ, such as Mal/Krap-D, are still newly-identified and may include other capabilities besides those noted in the below section. However, SpywareRemove.com malware analysts have compiled a short list of prominent attacks that are likely to result from Troj/JavaDl-NJ-related infections that aren't removed by anti-malware software in sufficient haste:

  • Backdoor vulnerabilities that allow criminals to control your PC by way of remote server-based contact. This contact will attempt to evade your firewall and may not show symptoms of its attacks even while your PC is being compromised.
  • Loss of personal information from phishing attacks, banker Trojan attacks, keylogging attacks and other spyware-related functions. Passwords for accounts from games, website management and/or banks are common targets.
  • Finally, PC threats that are installed by Troj/JavaDl-NJ also have a high probability of installing other PC threats, either included in their bodies or as files that are downloaded from remote servers.

SpywareRemove.com malware research team recommends that you use anti-malware software to identify and remove any Troj/JavaDl-NJ-installed PC threats, since their quantities may vary due to the potential installation capabilities in the original payload.

Technical Details

Additional Information

The following URL's were detected:
https://crypsearch.com/search.php?q
Loading...