Home Malware Programs Trojans Trojan.Win32.Vaklik.gax

Trojan.Win32.Vaklik.gax

Posted: November 25, 2009

Trojan.Win32.Vaklik.gax is a malicious Trojan that injects rootkit components into Windows processes and attempts to hides itself from detection. Trojan.Win32.Vaklik.gax also makes changes to Windows Explorer settings and downloads other malicious files from external servers. Trojan.Win32.Vaklik.gax can monitor user activities to obtain valuable information, specifically login information. Trojan.Win32.Vaklik.gax is a dangerous threat to any computer or system and should be removed immediately.

Aliases

Troj/Lineag-GQ (Sophos)
Mal/Autorun-K (Sophos)
Worm:Win32/Taterf.B (Microsoft)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\4tddfwq1.dll
    2 %Temp%\xvassdf.exe
    3 c:\autorun.inf
    4 c:\dcp6w.exe
    5 c:\ohdv.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\MADOWN][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
Loading...