Home Malware Programs Trojans TROJ_INJECT.JDT

TROJ_INJECT.JDT

Posted: March 12, 2010

TROJ_INJECT.JDT is a malicious Trojan program that injects itself into Windows system processes in order to bypass most firewall software. TROJ_INJECT.JDT will then contact remote websites and attempt to download additional malware onto your system without your permission or consent. TROJ_INJECT.JDT employs rootkit techniques to hide itself from visible system processes.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %User Temp%\mshmail.exe
    2 %User Temp%\svchost.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\HKEY..\..\..\..{RegistryKeys}Windows\CurrentVersion\Runmshmail = "%User Temp%\mshmail.exe -installkys"
Loading...