Home Malware Programs Trojans TR/DNSChanger.VJ.2

TR/DNSChanger.VJ.2

Posted: October 18, 2011

Threat Metric

Ranking: 19,167
Threat Level: 10/10
Infected PCs: 33
First Seen: October 18, 2011
Last Seen: January 10, 2025
OS(es) Affected: Windows

TR/DNSChanger.VJ.2 is a dangerous mutating Trojan which is generated to reset DNS settings of the targeted computer. TR/DNSChanger.VJ.2 is able to create and keep up enduring connections to some remote servers and might mutate into updated versions while existing on the corrupted PC system. TR/DNSChanger.VJ.2 may also download and install additional malware threats. TR/DNSChanger.VJ.2 allows attacker to obtain remote access to the affected machine. You should delete TR/DNSChanger.VJ.2 as soon as possible.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ProgramFiles%\PopinMV\PopinMVUpdate File name: %ProgramFiles%\PopinMV\PopinMVUpdate
Group: Malware file
%ProgramFiles%\Gen:Variant.Buzy.4104 File name: %ProgramFiles%\Gen:Variant.Buzy.4104
Mime Type: unknown/4104
Group: Malware file
%ProgramFiles%\PopinMV File name: %ProgramFiles%\PopinMV
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run PopinMVUpdate = "%ProgramFiles%\TR/DNSChanger.VJ.2"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths Path = "%ProgramFiles%\PopinMV\PopinMVUpdate" (Default) = "%ProgramFiles%\PopinMV\PopinMVUpdate\TR/DNSChanger.VJ.2"
Loading...