Home Malware Programs Trojans Trojan.Lodelit

Trojan.Lodelit

Posted: December 21, 2010

Trojan.Lodelit is a malicious Trojan which drops corrupt files on a compromised computer. Trojan.Lodelit is designed to open a large security loophole through which hundreds of malicious adware and spyware can be piped to your machine. Trojan.Lodelit opens a backdoor that allows the remote attacker to get the full control over the infected computer and this places any financial or banking information stored on your computer in severe jeopardy and represents a serious security risk. Remove Trojan.Lodelit before it steals your money.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\[RANDOM CHARACTERS].dll
    2 %UserProfile%\Application Data\[RANDOM CHARACTERS].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Win32load" = "%UserProfile%\Application Data\[RANDOM CHARACTERS].exe"HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"%UserProfile%\Application Data\[RANDOM CHARACTERS].exe" = "%UserProfile%\Application Data\[RANDOM CHARACTERS].exe:":Enabled:Win32load" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"%UserProfile%\Application Data\[RANDOM CHARACTERS].exe" = "%UserProfile%\Application Data\[RANDOM CHARACTERS].exe:":Enabled:Win32load"
Loading...