Home Malware Programs Trojans Geoload

Geoload

Posted: March 28, 2006

Geoload is a trojan designed to silently download from the Internet and install certain spywares and unsolicited applications. The threat regularly contacts a predefined web server in order to retrieve additional instructions and apply updated configuration settings. Geoload automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 chke.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonNotifychk
Loading...