Home Malware Programs Trojans Juny

Juny

Posted: March 28, 2006

Juny is a trojan that encrypts files of predefined types , so they can no longer be accessed by the user. It also drops a text file on the desktop containing the list of encrypted files. Upon execution, Juny shows a message in Russian warning the user that the computer is infected with the trojan. This message asks the victim to pay for decrypting files and send the ransom to a specified e-mail address. Juny automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 krnlmgr.exe
    2 krnlmngr.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTEventSystem.EventSystemPrivateDataFuckedBytesHKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunKernelManagerHKEY_LOCAL_MACHINESOFTWAREClassesEventSystem.EventSystemPrivateDataFuckedBytesHKEY_LOCAL_MACHINESOFTWAREClassesexefileOpenCommand(Default)=%System%krnlmgr.exe%1%*HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunKernelManager
Loading...