Home Malware Programs Trojans Trojan.VB.ews

Trojan.VB.ews

Posted: December 29, 2010

Trojan.VB.ews is a Computer Trojan horse that may use a PC's network to compromise the connected systems. Trojan.VB.ews may be installed through a system exploit and then allow access to the compromised system to outside attackers. Trojan.VB.ews could quite easily lead to theft of information. Any PC infected with Trojan.VB.ews is susceptible to slow performance and stability issues virtually leaving the computer user without a means of having full control over the computer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 apkruisi.dll
    2 Athan.exe
    3 brconcho.dll
    4 CalcImpSAT[1].exe
    5 dldesmos.dll
    6 geindigo.dll
    7 inandrom.dll
    8 javachelper.dll
    9 lspolysp.dll
    10 OPR.exe
    11 sesingul.dll
    12 swcupdate.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{46C82107-C059-4B5A-8BEE-361B06DB044C}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{6742CC3A-65E8-4ED9-B051-AA119195C7BE}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{7B618C0C-8D13-4F49-8559-BE04DC96899C}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{96F7F230-8ADE-4930-A88F-3547C6A30BFF}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{98A60C8C-2568-4029-9FB2-F2ED7E2DA8E8}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ AthanHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ExplorerHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ System FileHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows Log Agent
Loading...