Home Malware Programs Trojans Trojan.Win32.VB.ahhq

Trojan.Win32.VB.ahhq

Posted: August 10, 2010

Trojan.Win32.VB.ahhq is a malicious Trojan horse that may represent security risk for the compromised system or its network environment. Trojan.Win32.VB.ahhq uses backdoors to install contaminated files from the internet onto a compromised computer. Trojan.Win32.VB.ahhq may spread via drive-by downloads and does not require a user's permission to run on a computer. Trojan.Win32.VB.ahhq comes bundled with a malicious installation program. Remove Trojan.Win32.VB.ahhq as soon as it has been detected.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Baidu\Toolbar\BaiduBarX.dll %ProgramFiles%\Baidu\Toolbar\BaiduBarX_Tmp\BaiduBarX.dll
    2 %ProgramFiles%\Baidu\Toolbar\BaiduBarX_Tmp\BarBroker.exe
    3 %ProgramFiles%\Baidu\Toolbar\BaiduBarX_Tmp\rc.dll
    4 %ProgramFiles%\Baidu\Toolbar\BarBroker.exe
    5 %ProgramFiles%\Baidu\Toolbar\rc.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1f4de370-d627-11d1-ba4f-00a0c91eedba}\DefaultIcon][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1f4de370-d627-11d1-ba4f-00a0c91eedba}\ShellFolder][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1f4de370-d627-11d1-ba4f-00a0c91eedba}][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{1f4de370-d627-11d1-ba4f-00a0c91eedba}]
Loading...