Home Malware Programs Trojans Win-Trojan/Downloader.141317

Win-Trojan/Downloader.141317

Posted: June 9, 2010

Win-Trojan/Downloader.141317 is a Trojan dropper that installs other forms of PC threats after compromising your ocmputer's security. Some variants of Win-Trojan/Downloader.141317 may also be backdoor Trojans that allow hackers to gain access to your PC for the purposes of facilitating crimes (such as theft of personal information). SpywareRemove.com malware experts have noted that the majority of Win-Trojan/Downloader.141317 infections have attacked computers in France and Croatia, and you may wish to be particularly-wary of potential Win-Trojan/Downloader.141317 attacks if you live in either of those regions. In most cases, the only symptoms of Win-Trojan/Downloader.141317 infection will be any side effects that are caused by its payload (such as the visible presence of rogue security software or web browser redirects), and you should typically-use anti-malware software to detect or remove Win-Trojan/Downloader.141317 with perfect accuracy.

Why Win-Trojan/Downloader.141317 May Be the First of Many Computer Problems

Win-Trojan/Downloader.141317 is distributed by P2P networks and pirated software websites, typically as part of a package with another application (such as a password-cracking program or mislabeled picture files). Different versions of Win-Trojan/Downloader.141317 can display subtly-differing traits, but most versions of Win-Trojan/Downloader.141317 will engage in 'dropper' behavior that installs browser hijackers, spyware, rogue security products and other types of malicious software. SpywareRemove.com malware researchers warn to be cautious about opening files from untrustworthy sources to avoid the possibility of Win-Trojan/Downloader.141317 infection, especially with regards to files that are deliberately-criminal in purpose.

Win-Trojan/Downloader.141317 itself may show few to no signs of its presence, but you may be able to detect Win-Trojan/Downloader.141317 by noting the symptoms of the programs that Win-Trojan/Downloader.141317 installs, which can include:

  • Browser redirect attacks that force your web browser to load malicious websites or fake warning screens.
  • Fake infection alerts and other forms of fraudulent and unusual pop-up messages.
  • The presence of unusual memory processes in Task Manager, including extra copies of normal files like svchost.exe or strangely-high memory usage.
  • Changes to your system settings, particularly settings that are related to your network or firewall security.
  • Problems running PC security programs (including anti-virus scanners and diagnostic tools).

Reversing Win-Trojan/Downloader.141317's Domination of Your Hard Drive

Win-Trojan/Downloader.141317 may take a variety of steps to insure that Win-Trojan/Downloader.141317 can't be easily-noticed, such as hiding inaccurately-named files in sub-folders of your Windows directory or launching itself as a hidden process in the background when your operating system first starts. Due to these malicious safeguards, as well as the possibility of accompanying PC threats, SpywareRemove.com malware analysts recommend that you find and delete Win-Trojan/Downloader.141317 by using standard anti-malware software and strategies.

Win-Trojan/Downloader.141317 may be detected by different names, depending on both the variant of Win-Trojan/Downloader.141317 and the type of anti-malware scanner that you use to detect and get rid of Win-Trojan/Downloader.141317. Some of Win-Trojan/Downloader.141317's aliases include Backdoor.Win32.SdBot, Backdoor.Win32.Bifrose.aci, Mal/Refreso-B and Trojan.Win32.Antavmu.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\addons.dat
    2 %System%\Explorer\Explorer.exe
    3 %System%\Explorer\logg.dat

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Explorer][HKEY_LOCAL_MACHINE\SOFTWARE\Explorer][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}]
Loading...