Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Trojan.VBKrypt.YHR

 

 

Name:

Trojan.VBKrypt.yhr

Descr. Added:

July 12, 2012

Type:

Trojan

Risk:

Low

Payload:

N/A

At risk systems:

Windows 95/98/ME/XP/NT/2003

 

 

Malware problems?   We can help.  Free Removal Tools.

 

 

Description:

 

When Trojan.VBKrypt.yhr is executed, it performs the following activities:

After execution, it creates the following files:
%Temp%\g0dllp.exe
%Temp%\g0dllrp.exe

It creates/modifies the following registry entries:

"%Temp%\g0dllrp.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\g0dllr:

"%Temp%\g0dllp.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\g0dll

"Explorer.exe %Temp%\g0dllp.exe"
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell:

"C:\WINDOWS\system32\userinit.exe,%Temp%\g0dllp.exe"
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit:

 

 

 

 

 

 

 

 
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 - Industry Leading Endpoint Security Solution

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4