Home Malware Programs Trojans TrojanDropper:Win32/Microjoin.gen!B

TrojanDropper:Win32/Microjoin.gen!B

Posted: January 4, 2010

TrojanDropper:Win32/Microjoin.gen!B is a Trojan Downloader program which aims to drop malware onto infected computers. TrojanDropper:Win32/Microjoin.gen!B is mostly installed through a vulnerability exploit or other tricky methods. TrojanDropper:Win32/Microjoin.gen!B helps to download and install other undesired software onto a victim's PC. TrojanDropper:Win32/Microjoin.gen!B may download adware, spyware or other malware from multiple servers or sources on the Internet.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\5_odbn.exe
    2 %Temp%\teste1_p.exe
    3 %Temp%\teste2_p.exe
    4 %Temp%\teste3_p.exe
    5 %Temp%\teste4_p.exe
    6 %Windir%\amoumain.exe
    7 %Windir%\ctfmon.exe
    8 %Windir%\lsass.exe
    9 %Windir%\odbn.exe
    10 %Windir%\servicelayer.exe
    11 %Windir%\tmp2064969.log
    12 %Windir%\tmp6067608.log
    13 %Windir%\tmp8039258.log
    14 %Windir%\tmp9948651.log

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]HKEY..\..\..\..{RegistryKeys}NotifyDownloadComplete = "yes"amoumain = "%Windir%\amoumain.exe"ctfmon = "%Windir%\ctfmon.exe"lsass = "%Windir%\lsass.exe"odbny = "%Windir%\odbn.exe"servicelayer = "%Windir%\servicelayer.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Loading...