Home Malware Programs Trojans Trojan.VB.fru

Trojan.VB.fru

Posted: December 29, 2010

Trojan horse parasites typically infiltrate vulnerable computers. A detected threat called Trojan.VB.fru is a Trojan parasite that may enter a system through a security exploit. Once the computer is infected with Trojan.VB.fru, it is then susceptible to downloading other malware onto the computer without knowledge of the computer user. This can be a very dangerous situation because Trojan.VB.fru may also be able to connect a remote hacker to the infected system potentially allowing data to be stolen. Removal of Trojan.VB.fru is recommended to be performed with a good spyware removal tool.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 apkruisi.dll
    2 Athan.exe
    3 brconcho.dll
    4 dldesmos.dll
    5 geindigo.dll
    6 inandrom.dll
    7 javachelper.dll
    8 lspolysp.dll
    9 sesingul.dll
    10 swcupdate.exe
    11 wd[1].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{46C82107-C059-4B5A-8BEE-361B06DB044C}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{6742CC3A-65E8-4ED9-B051-AA119195C7BE}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{7B618C0C-8D13-4F49-8559-BE04DC96899C}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{96F7F230-8ADE-4930-A88F-3547C6A30BFF}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{98A60C8C-2568-4029-9FB2-F2ED7E2DA8E8}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ AthanHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ExplorerHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ System FileHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows Log Agent
Loading...