Home Malware Programs Viruses VirTool:Win32/VBInject.JJ

VirTool:Win32/VBInject.JJ

Posted: March 21, 2011

VirTool:Win32/VBInject.JJ is a mischievous computer virus which uses malicious tricks to download infected malware from the web. VirTool:Win32/VBInject.JJ may install malignant system processes and conceal itself from firewall and anti-virus software. VirTool:Win32/VBInject .JJ tries to spread by exploiting local network shares. VirTool:Win32/VBInject.JJ uses a malicious code with the rootkit-specific methods generated to disguise the software existence on the system.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\iexplorr\logg.dat
    2 %System%\iexplorr\system

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\mozillaHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}HKEY_LOCAL_MACHINE\SOFTWARE\mozilla[HKEY_CURRENT_USER\Software\mozilla]klg = 01[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}]stubpath = "%System%\iexplorr\system s"[HKEY_LOCAL_MACHINE\SOFTWARE\mozilla]HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideoHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideonck = ED 1B E6 27 B9 28 D6 32 74 C3 CD 74 FA 93 5B 67
Loading...