Home Malware Programs Trojans TROJ_MONDER.RON

TROJ_MONDER.RON

Posted: July 16, 2010

TROJ_MONDER.RON is a malicious Trojan that runs in the background and allows hackers remote access to an infected PC. TROJ_MONDER.RON modifies other files on the system by infecting or overwriting them. TROJ_MONDER.RON can also download corrupt files to the local computer that may represent security risk. TROJ_MONDER.RON may be installed on a system when users unknowingly visit malicious websites and uses rootkit technology to evade scanners. TROJ_MONDER.RON poses a severe threat to any computer and should be removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\sshnas21.dll
    2 %Windows%\cwohia.exe
    3 {35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
    4 {8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\SOFTWARE\XMLHKEY_CURRENT_USER\Software\JDK55WFMZYHKEY_CURRENT_USER\Software\Microsoft\HKEY_CURRENT_USER\Software\W34BCG2GRJHKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSHNASJDK55WFMZY = "%User Temp%\cdx.exe"Windows\CurrentVersion\Run
Loading...