Our team of researches surfs the Internet on an everyday basis in search of the latest registry news and relevant information useful to visitors. This site strives to provide exciting registry information with two basic principles; Simplicity and Quality, with reference to the best information on registries.
The writers of the site present articles illustrated with images, while ensuring that the articles are both clear and concise in order to provide professional, yet easy to understand articles. Registry products and problems are analyzed and evaluated so as to present visitors with professional and factual articles. More...
May
25th

Trojan.Metajuan: Don’t let your PC Get Infected!

Author: Indre | Files under Fix slow PC

Whenever you switch on your PC your antivirus shows you a warning indicating the presence of a Trojan. Due to this infection, every time you use your search engine you are redirected to casino and porn sites or in some cases the search pages are not displayed at all. Does it really irritate you? Bad news, looking at the above symptoms you could very well be infected with Trojan.Metajuan.

  Type: Trojan
  Infection Length: 36,733 bytes
  Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP

Threat Alias
Trojan.Metajuan
Trojan.Win32.Monder.auxz
Trojan.Win32.Vundo
Trojan:Win32/Conhook.D
Vundo.gen.ab

Table 1.Threat Alias

The fact is that you may catch Trojan.Metajuan in the following ways; the trojan can be dropped by other malware or downloaded from malicious Web sites while using Internet Explorer exploits.

Once the Trojan is executed, it will create the following registry entry:

HKEY_CLASSES_ROOT\CLSID\68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50}\InprocServer32\”Default” = “%Temp%\[NAME OF TROJAN EXECUTABLE].dll”

After that, the Trojan creates the following registry subkey to register itself as a Browser Helper Object:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper01_-_trojan_horse.jpg Objects\{68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50}

Finally, Trojan.Metajuan contacts the following site:

[http://]65.243.103.58/trafc-2/rfe[REMOVED]

In addition, the Trojan is able to download potentially malicious files on to the compromised computer.

To avoid computer problems and not cause serious harm to your system, be wary of computer infections such as Trojan.Metajuan.

Resources:
Alias names of the Trojan
Details of the Trojan.Metajuan
Additional information on Trojan. Metajuan

One response. Wanna say something?

  1. KleinDenise28
    May 31, 2010 at 14:02:06
    #1

    People deserve very good life time and <a href="http://lowest-rate-loans.com/topics/cre dit-loans">credit loans</a> or collateral loan would make it much better. Because people's freedom is grounded on money.

Post a Comment

Security Code: