Home Malware Programs Trojans Joex

Joex

Posted: March 28, 2006

Joex is a trojan that changes Internet Explorer default start page to a web site on the joyiex.com domain, disables the Windows Task Manager and modifies certain computer settings. The spyware has the ability to update itself via the Internet.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 commamd.exe
    2 ctfnom.exe
    3 lsasa.exe
    4 svohost.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTxtfileshellopencommand=%System%lsasa.exe%1HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableTaskMgr=1HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunctfnom.exe=%Windir%svohost.exeHKEY_CURRENT_USERSoftwarePoliciesInternetExplorerControlPanelHomePage=1HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionWinlogonShell=explorer.execommamd.exe
Loading...