









 |
W32/Jaan.L Trojan
| Name |
W32/Jaan.L Trojan |
| Aliases |
BDS/Jaan.L, Backdoor.Jaan.l, Win32/Hangpi.D, Worm:Win32/Hangping.B, W32.SillyDC |
| Discovered on |
August 01, 2008 |
Virus Information - W32/Jaan.L Trojan:
W32/Jaan.L is a trojan. The trojan will infect Windows systems.
The trojan may be dropped by other malware or may be downloaded from remote website by other malware. It may also be downloaded unknowingly by a user while visiting malicious Website.
Upon execution, the trojan drops the following files:
services.exe in the Windows\Security folder,
myproc.dll in the Windows folder,
kernelpr.dll in the Windows folder,
setupconfig.dat in the Windows folder.
The trojan modifies registry at the following location to load itself during each startup;
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\services
It also modifies registry at the following locations:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CE206541-8713-4639-B33D-11A750BF7915}\1.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CB7ABE87-D14C-444C-9DAA-74AC9907BF8B}\InprocServer32

|