Home Rogue Websites Podmena

Podmena

Posted: June 25, 2009

Podmena is a trojan virus that may be advertised as a video codec or a useful and beneficial program. Typically, Podmena is distributed through email, rogue websites, peer-to-peer networks, etc. Once installed, Podmena will alter registry entries and create various malicious files on your PC, causing Podmena to be a significant security threat.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 podmena.bat
    2 podmena.dll
    3 podmena.sys

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHostHKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\podmena\Parameters]HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\podmenadrv]ImagePath = "\??\%ProgramFiles%\podmena\podmena.sys"ServiceDll = "%ProgramFiles%\podmena\podmena.dll"podmena = "podmena"
Loading...