Sophos

Sophos blogs

Troj/Jubik-A

Aliases
  • Trojan.Win32.Small.fb
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 18 March 2006 17:36:33 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Jubik-A is a Trojan for the Windows platform.

Troj/Jubik-A includes functionality to download files from the internet. Troj/Jubik-A may inject code into other Windows processes in an attempt to avoid detection. Troj/Jubik-A is a Trojan for the Windows platform.

Troj/Jubik-A includes functionality to download files from the internet. Troj/Jubik-A may inject code into other Windows processes in an attempt to avoid detection.

When first run Troj/Jubik-A copies itself to <System>\jb???.exe, where ??? are 3 random letters.

The following registry entry is created to run jb???.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
jb???.exe
<System>\jb???.exe

Troj/Jubik-A modifies the following registry entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer \BrowseNewProcess
BrowseNewProcess
yes

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer