Threat Information for "Trojan.Inject.409"
| Summary | Top |
- Name: Trojan.Inject.409
- Aliases:
- Date Discovered: 2008-02-26
- Protection Added: 2008-03-10
| Description | Top |
-- Ease of Removal 1: Creates new registry entries with consistent data 2: Consistent file contents 3: Consistently named 4: Injects DLLs into running processes 5: Uses redundant/watcher processes -- Privacy Risks/Security Changes 1: Mimics legitimate file names -- Damage/Intrusion/Annoyance 1: Creates new files -- Propagation/Saturation 1: Spreads through Peer-2-Peer software
| Technical Details | Top |
- Added Directory/File:
FilePath: %WINDIR%\IMG-????.zip - Added Directory/File:
FilePath: %WINDIR%\system\explorer.exe - Added Registry Data:
Key: HKLM\%CURRENTVERSIONREG%\Run Value: [RANDOM VALUE] Data: %WINDIR%\system\explorer.exe

