Home Malware Programs Trojans Junet

Junet

Posted: March 28, 2006

Junet is a trojan that steals login names, passwords and account details that the user enters on certain web sites including secure resources. Gathered data is silently transferred to a predetermined remote server. Junet automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 usrh.exe
    2 winuser.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEU_CURRENT_USERSoftwareMicrosoftWindowsNTCurrentVersionRun\%Windows%winuser.exeHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunuserlogon=%System%usrh.exeHKEY_LOCAL_MACHINESOFTWARENVMark
Loading...