Trojan.Win32.DNSChanger.gn

tag:Trojans  

Once launched, the Trojan injects its code into the memory of the process which has the following mutex in the system registry:

{BD96C556-65A3-11D0-983A-00C04FC29E36}

The Trojan exploits a vulnerability in the ActiveX XMLHTTP component to download a file from the following URL:

http://www.***fch.com/admin/picimg/qq.exe

At the moment of writing, this link was not working.

The Trojan exploits a vulnerability in the

If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:

  1. Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
  2. Delete the following files: %Temp%\svchost.exe %Temp%\svchost.vbs
  3. Disable the vulnerable ActiveX object (see How to stop an ActiveX control from running in Internet Explorer
  4. Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).

This Trojan downloads other files via the Internet and launches them for execution on the victim machine without the user’s knowledge or consent. It is an HTML page which contains Visual Basic Script. It is 1445 bytes in size.

Payload

©Virus-Encyclopedia.com All Rights Reserved.