Home Malware Programs Trojans Ruindem

Ruindem

Posted: March 28, 2006

Ruindem is a trojan, which downloads from the Internet and executes malicious files, sends the web browser to undesirable insecure web sites and blocks access to popular web resources. It also collects computer and network information and transfers it to a predetermined server. Ruindem may open a pornographic site and show unsolicited advertisements. The spyware automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 dm[X].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRundm[X].exeuins
Loading...