Home / malwarePDF  

Win32.Jacksud.A


First posted on 21 November 2011.
Source: BitDefender

Aliases :

Win32.Jacksud.A is also known as Email-Worm.Win32.Warezov.om, Win32/Cekar.C, Trojan.Downloader.Agent.NUY.

Explanation :

Once executed, the virus tries to download and execute a file from http://www.KILLVC.net/[removed].exe, which is a file infector that infects other executables with the Win32.Jacksud.A virus. Also it drops a .dll file onto the root directory of disk C:. This file, called i0.sys is detected as Win32.Worm.Fujacks.AR, and it is loaded into memory and executed by the file infector itself.

Last update 21 November 2011

 

TOP