









 |
W32/Exchanger.LA Trojan
| Name |
W32/Exchanger.LA Trojan |
| Aliases |
Trojan-Downloader.Win32.Exchanger.la, I-Worm/Nuwar.V, Win32/Collet.DJ, Mal/EncPk-DA, Trojan.DL.Exchanger.BZ |
| Discovered on |
August 21, 2008 |
Virus Information - W32/Exchanger.LA Trojan:
W32/Exchanger.LA is a trojan. The trojan will infect Windows systems.
The trojan may be dropped by other malware or may be downloaded from remote website by other malware. It may also be downloaded unknowingly by a user while visiting malicious Website.
Upon execution, the trojan drops CbEvtSvc.exe in the Windows System folder.
The trojan modifies registry at the following locations:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CbEvtSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CbEvtSvc\ImagePat

|