Home Malware Programs Trojans ZenDown

ZenDown

Posted: March 28, 2006

ZenDown is a destructive spyware, which acts by modifying computer registry by adding several values to it. These values make the Windows shutdown each time it is started. This technique makes it completely impossible to use Windows normally, that's why a careful attitude towards such spywares is always recommended.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ihateyou.exe
    2 rundll32.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}SHExitWindowsEx1Shutdown2C:WindowsShutdownC:Windowsihateyou.exeundll32.exeshell32
Loading...