Home Malware Programs Trojans Troj/DwnLdr-KJW

Troj/DwnLdr-KJW

Posted: November 23, 2012

Threat Metric

Threat Level: 10/10
Infected PCs: 80
First Seen: November 25, 2012
OS(es) Affected: Windows

Troj/DwnLdr-KJW is a backdoor trojan that poses as a Thanksgiving screensaver while it attempts to compromise your PC's security. Like a typical backdoor trojan, Troj/DwnLdr-KJW intends to allow criminals to access and control your computer through a remote Command & Control server, and may make additional attacks (such as stealing passwords, blocking programs or installing other malware). Although it attempts to conceal itself from casual detection, Troj/DwnLdr-KJW can be deleted with appropriate anti-malware programs. However, SpywareRemove.com malware researchers prefer that you avoid the fake screensaver e-mails that Troj/DwnLdr-KJW uses to distribute itself – since deleting these e-mails on sight will save you the trouble of needing to remove a Troj/DwnLdr-KJW infection at all.

Why Digging Into That Digital Turkey Will Leave a Bad Taste in Your Mouth

As another to the roster of e-mail-distributed trojans, Troj/DwnLdr-KJW's delivery strategy isn't anything unusual – except for the holiday timing. Troj/DwnLdr-KJW attacks were first noted late November of 2012, just in time for Thanksgiving. Accordingly, Troj/DwnLdr-KJW's spam e-mails all were themed to look like downloads for Thanksgiving screensavers. While this file uses the screensaver file type (SCR) and even displays pictures, SpywareRemove.com malware researchers have found that this isn't all it does.

Detected by the names Troj/DwnLdr-KJW, Gen:Trojan.Heur.RP.iqW@aqOxJznj and Gen:Variant.Symmi.5453, this backdoor trojan is designed to attack Windows computers. While its victims are distracted by visions of autumn leaves and roasted turkeys, Troj/DwnLdr-KJW installs a malicious DLL file and sets itself to launch with Windows (by making changes to the Registry). After that, Troj/DwnLdr-KJW begins contacting a remote server that can be used for a range of harmful purposes.

Current Troj/DwnLdr-KJW samples show that Troj/DwnLdr-KJW also makes queries to Google Mail and Jobster. SpywareRemove.com malware experts note that this may cause accessibility issues for your browser when you try to reach these websites.

Why Troj/DwnLdr-KJW is Worse for Your PC Than a Little Weight Gain

While a real turkey may leave you on the treadmill for longer than you'd like, Troj/DwnLdr-KJW is a high-level threat to your computer and includes all the basic functions that would be required to neuter your PC's security and/or privacy. Attacks that SpywareRemove.com malware experts warn you may be exposed to during Troj/DwnLdr-KJW infections include, but aren't restricted to:

  • Changes to your system settings to redirect your browser, block programs or disable security features.
  • The installation of other malware (banking trojans, ransomware trojans, rogue anti-virus scanners, etc).
  • Tracking and theft of personal data such as account login info.

Beyond the fake screensaver features that are used to gain access to your PC, Troj/DwnLdr-KJW doesn't display symptoms of its attacks or, in fact, of its presence (which should be assumed to be open, unless you've taken steps to disable Troj/DwnLdr-KJW). Since Troj/DwnLdr-KJW, as a newly-identified trojan, may require the latest databases for its complete removal, Troj/DwnLdr-KJW should be deleted by updated anti-malware products as necessary.

Loading...