Home / malware Win32.Jacksud.A
First posted on 21 November 2011.
Source: BitDefenderAliases :
Win32.Jacksud.A is also known as Email-Worm.Win32.Warezov.om, Win32/Cekar.C, Trojan.Downloader.Agent.NUY.
Explanation :
Once executed, the virus tries to download and execute a file from http://www.KILLVC.net/[removed].exe, which is a file infector that infects other executables with the Win32.Jacksud.A virus. Also it drops a .dll file onto the root directory of disk C:. This file, called i0.sys is detected as Win32.Worm.Fujacks.AR, and it is loaded into memory and executed by the file infector itself.
Last update 21 November 2011