Home Malware Programs Trojans Generic VB.c

Generic VB.c

Posted: February 17, 2010

Generic VB.c is a malicious Trojan infection that injects itself into a legitimate running process on the infected computer. Generic VB.c can load corrupt programs without being detected by an anti-virus application. Generic VB.c also modifies the system registry and drops malicious files and folders on the compromised computer. Use a reliable anti-malware program to rid your PC Generic VB.c immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %SysDir%\system32
    2 %SysDir%\system32\server.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\policies\Explorer\RunHKEY_USERS\S-1-(Varies)\Software\Microsoft\Windows\Current Version\Policies\Explorer\Run[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{1AVWLUYY-4FJI-4P57-4103-R041TITO3LP3}\] "StubPath" ="%SysDir%\system32\server.exe"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\policies\Explorer\Run\] "Policies"="%SysDir%\system32\server.exe"[HKEY_USERS\S-1-(Varies)-1005\Software\Microsoft\Windows\Current Version\Policies\Explorer\Run\] "Policies"= "%SysDir%\system32\server.exe"
Loading...