Home Malware Programs Trojans Trojan.Win32.VB.aodb

Trojan.Win32.VB.aodb

Posted: August 8, 2011

Trojan.Win32.VB.aodb is a Trojan that tries to propagate over the affected computer network environment. Trojan.Win32.VB.aodb executes numerous activities on a targeted computer system, for example, changes infected PC system to block users from accessing legitimate security websites. Trojan.Win32.VB.aodb changes system settings to expose PC system to more attacks. Trojan.Win32.VB.aodb will configure itself to run every time you start your computer. You need to remove Trojan.Win32.VB.aodb by using a powerful anti-virus software.

Aliases

TrojanWin32VBaodb

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Programs%\winlogon.exe File name: %Programs%\winlogon.exe
File type: Executable File
Mime Type: unknown/exe
%Programs%\Startup\winlogon.exe File name: %Programs%\Startup\winlogon.exe
File type: Executable File
Mime Type: unknown/exe
%CommonStartMenu%\winlogon.exe File name: %CommonStartMenu%\winlogon.exe
File type: Executable File
Mime Type: unknown/exe
%CommonPrograms%\winlogon.exe File name: %CommonPrograms%\winlogon.exe
File type: Executable File
Mime Type: unknown/exe
%CommonPrograms%\Startup\winlogon.exe File name: %CommonPrograms%\Startup\winlogon.exe
File type: Executable File
Mime Type: unknown/exe
%UserProfile%\56D616E427563755\wlo.exe File name: %UserProfile%\56D616E427563755\wlo.exe
File type: Executable File
Mime Type: unknown/exe
%UserProfile%\56D616E427563755\winlogon.exe File name: %UserProfile%\56D616E427563755\winlogon.exe
File type: Executable File
Mime Type: unknown/exe
%StartMenu%\winlogon.exe File name: %StartMenu%\winlogon.exe
File type: Executable File
Mime Type: unknown/exe

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\anti-trojan.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\amon9x.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\amon.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivirus.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\antigen.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alogserv.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alertsvc.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\alerter.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ahnsd.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ackwin32.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a2servic.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ExplorerHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\SvcHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentw.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\advxdwin.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\acs.exe
Loading...