Home Malware Programs Rogue Anti-Spyware Programs TrustNinja

TrustNinja

Posted: August 26, 2009

TrustNinja (also referred to as Trust Ninja) is a fake system optimization tool. It masquerades as a useful program, but is nothing of the sort, only seeking to gain your trust. Typically TrustNinja states that your computer is infected or has various problems, and then prompts you to purchase the full version in order to combat these imaginary issues.

File System Modifications

  • The following files were created in the system:
    # File Name File Size (bytes) File Hash
    1 %Documents and Settings%\All Users\Desktop\TrustNinja.lnk N/A N/A
    2 %Documents and Settings%\All Users\Start Menu\Programs\TrustNinja\1 TrustNinja.lnk N/A N/A
    3 %Documents and Settings%\All Users\Start Menu\Programs\TrustNinja\2 Homepage.lnk N/A N/A
    4 %Documents and Settings%\All Users\Start Menu\Programs\TrustNinja\3 Uninstall.lnk N/A N/A
    5 %Program Files%\TrustNinja Software N/A N/A
    6 %ProgramFiles%\TrustNinja Software\TrustNinja N/A N/A
    7 %ProgramFiles%\TrustNinja Software\TrustNinja\data.bin N/A N/A
    8 %ProgramFiles%\TrustNinja Software\TrustNinja\license.txt N/A N/A
    9 %ProgramFiles%\TrustNinja Software\TrustNinja\TrustNinja.exe N/A N/A
    10 %ProgramFiles%\TrustNinja Software\TrustNinja\TrustNinjaSvc.exe N/A N/A
    11 %ProgramFiles%\TrustNinja Software\TrustNinja\uninstall.exe N/A N/A
    12 %Temp%\nsm2.tmp\nsProcess.dll N/A N/A
    13 %Temp%\nsm2.tmp\nsSCM.dll N/A N/A
    14 TrustNinja N/A N/A
    15 TrustNinja.exe 724,992 c9f6764aede6c4384af2d50bf00e6da8
    16 TrustNinja.lnk N/A N/A
    17 TrustNinjaSvc.exe 65,536 e92f901fb0a487d9aac6ae40b8e05d56

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “TrustNinja”HKEY_CURRENT_USER\Software\TrustNinjaHKEY_LOCAL_MACHINE\SOFTWARE\TrustNinjaHKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TRUSTNINJASVCHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TRUSTNINJASVC\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TRUSTNINJASVC\0000\ControlHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrustNinjaSvcHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrustNinjaSvc\EnumHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrustNinjaSvc\SecurityHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TRUSTNINJASVCHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TRUSTNINJASVC\0000HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TRUSTNINJASVC\0000\ControlHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrustNinjaSvcHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrustNinjaSvc\EnumHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrustNinjaSvc\SecurityHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}TrustNinja

Additional Information on TrustNinja

  • The following paths were detected:
    # Path
    1 %ProgramFiles%\TrustNinja Software
Loading...