









 |
W32/Dload.JT Trojan
| Name |
W32/Dload.JT Trojan |
| Aliases |
TROJ_DLOADR.JT |
| Discovered on |
August 26, 2008 |
Virus Information - W32/Dload.JT Trojan:
W32/Dload.JT is a trojan. The trojan will infect Windows systems.
The trojan may be dropped by other malware or may be downloaded from remote website by other malware. It may also be downloaded unknowingly by a user while visiting malicious Website.
Upon execution, the trojan drops the following files:
XP-542ADE6B.EXE in the Windows System folder,
com.run in the Windows System folder,
dp1.fne in the Windows System folder,
eAPI.fne in the Windows System folder,
internet.fne in the Windows System folder,
krnln.fnr in the Windows System folder,
og.dll in the Windows System folder,
og.edt in the Windows System folder,
RegEx.fnr in the Windows System folder,
shell.fne in the Windows System folder,
spec.fne in the Windows System folder,
ul.dll in the Windows System folder.
The trojan modifies registry at the following location to load itself during each startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\XP-542ADE6B
It also tries to access remote Web sites to download the following file:
http://www.(Blocked)n.com/ul.htm

|