TrojanSpy:Win32/VBStat.AD is dropped as a component of Worm:Win32/RJump.F
. Its purpose is to execute Win32/RJump.F at each Windows start.
This trojan is a component of Worm:Win32/RJump.F. When Worm:Win32/RJump.F is executed, it may drop the following files:
- %windir%\mdm.exe - detected as TrojanSpy:Win32/VBStat.AD
- %windri%\svchost.exe - detected as Worm:Win32/RJump.F
- %windir%\svchost.ini - data file used by Worm:Win32/RJump.F
Worm:Win32/RJump.F executes the dropped component "mdm.exe" which modifies the registry to launch Win32/RJump.F at each Windows start.
Adds value: "SVCHOST"
With data: "%windir%\mdm.exe"
To subkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
When TrojanSpy:Win32/VBStat.AD executes, it uses ShellExecute to launch "%windir%\svchost.exe" which is the dropped copy of Worm:Win32/RJump.F.
For more information about Worm:Win32/RJump.F, please see elsewhere in our encyclopedia.
Analysis by Patrik Vicol