Home › Forums › Software Discussions › General Software Topics › Trojun.Goldun
-
Trojun.Goldun
Posted by Simon Kay on 9 March 2006 at 04:18Does anybody know what to do with this?
I’m trying to resurrect a laptop that caught this virus a while back. Never having had the time to do anything about it but now needing the laptop I reckon I should exorcise it. But how?
What does the virus affect?
Any answers welcomed.
Thanks,
Simon.
Simon Kay replied 19 years, 7 months ago 4 Members · 7 Replies -
7 Replies
-
I don’t know Nick.
There’s so much on it that would be disastrous if I lost it doing a system thingy. I’m not game to try, I’m not knowledgable enough.
Might just leave it alone and abuse it everytime it comes up. Or I could fork out the $xxx to get the latest updated version of Norton and hope it does it.
Cheers,Simon.
-
When Trojan.Goldun is executed, it performs the following actions:
Copies itself as %Windir%\wmedia16.exe.
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
Adds the value:
“Shell” = “%Windir%\wmedia16.exe”
to the following registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Monitors Internet Explorer windows and steals user’s authentication information. It adds the following strings in the address bar:
e-gold.com/acct/acct.asp
e-gold.com/acct/accountinfo.asp
e-gold.com/acct/login.htmlArrives in an email message.
The email will have the following characteristics:
From: E-gold
Subject:
Attention! E-gold service pack
MS Windows/Critical ErrorAttachment:
setup.zip (contains the file setup.exe)
MsWindowsUpdate.rar (contains the file MsWindowsUpdate.exe)Displays the archived file as an installer that patches the system but it actually drops and executes wmedia16.exe.
-
Try this link mate…
http://www.symantec.com/home_homeoffice/index.html
then > top things to do >free scan for viruses > then follow the instruction’s… good luck!
Nick.
-
W 😮 W Dale,
So you know a bit then, eh? 😀
Thanks for the explaination, when it sinks in I’m sure it will be invaluable. Presumably it’s not quite as easy as going into the relevant directories and deleting what you have told me?
Thanks to you too Nick. I’ll follow that link and see what happens.
Cheers,
Simon.
Log in to reply.