Troj/DwnLdr-KJW
Posted: November 23, 2012
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
| Threat Level: | 10/10 |
|---|---|
| Infected PCs: | 80 |
| First Seen: | November 25, 2012 |
|---|---|
| OS(es) Affected: | Windows |
Troj/DwnLdr-KJW is a backdoor trojan that poses as a Thanksgiving screensaver while it attempts to compromise your PC's security. Like a typical backdoor trojan, Troj/DwnLdr-KJW intends to allow criminals to access and control your computer through a remote Command & Control server, and may make additional attacks (such as stealing passwords, blocking programs or installing other malware). Although it attempts to conceal itself from casual detection, Troj/DwnLdr-KJW can be deleted with appropriate anti-malware programs. However, SpywareRemove.com malware researchers prefer that you avoid the fake screensaver e-mails that Troj/DwnLdr-KJW uses to distribute itself – since deleting these e-mails on sight will save you the trouble of needing to remove a Troj/DwnLdr-KJW infection at all.
Why Digging Into That Digital Turkey Will Leave a Bad Taste in Your Mouth
As another to the roster of e-mail-distributed trojans, Troj/DwnLdr-KJW's delivery strategy isn't anything unusual – except for the holiday timing. Troj/DwnLdr-KJW attacks were first noted late November of 2012, just in time for Thanksgiving. Accordingly, Troj/DwnLdr-KJW's spam e-mails all were themed to look like downloads for Thanksgiving screensavers. While this file uses the screensaver file type (SCR) and even displays pictures, SpywareRemove.com malware researchers have found that this isn't all it does.
Detected by the names Troj/DwnLdr-KJW, Gen:Trojan.Heur.RP.iqW@aqOxJznj and Gen:Variant.Symmi.5453, this backdoor trojan is designed to attack Windows computers. While its victims are distracted by visions of autumn leaves and roasted turkeys, Troj/DwnLdr-KJW installs a malicious DLL file and sets itself to launch with Windows (by making changes to the Registry). After that, Troj/DwnLdr-KJW begins contacting a remote server that can be used for a range of harmful purposes.
Current Troj/DwnLdr-KJW samples show that Troj/DwnLdr-KJW also makes queries to Google Mail and Jobster. SpywareRemove.com malware experts note that this may cause accessibility issues for your browser when you try to reach these websites.
Why Troj/DwnLdr-KJW is Worse for Your PC Than a Little Weight Gain
While a real turkey may leave you on the treadmill for longer than you'd like, Troj/DwnLdr-KJW is a high-level threat to your computer and includes all the basic functions that would be required to neuter your PC's security and/or privacy. Attacks that SpywareRemove.com malware experts warn you may be exposed to during Troj/DwnLdr-KJW infections include, but aren't restricted to:
- Changes to your system settings to redirect your browser, block programs or disable security features.
- The installation of other malware (banking trojans, ransomware trojans, rogue anti-virus scanners, etc).
- Tracking and theft of personal data such as account login info.
Beyond the fake screensaver features that are used to gain access to your PC, Troj/DwnLdr-KJW doesn't display symptoms of its attacks or, in fact, of its presence (which should be assumed to be open, unless you've taken steps to disable Troj/DwnLdr-KJW). Since Troj/DwnLdr-KJW, as a newly-identified trojan, may require the latest databases for its complete removal, Troj/DwnLdr-KJW should be deleted by updated anti-malware products as necessary.
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.