About Trojan Visages
Visages is a Trojan Horse that does not copy
itself, drop files, or have a malicious payload.
When this Trojan is run, it causes continuous
activity on the A: drive.
The Trojan was written in Microsoft Visual
Basic.
When Visages is run, it performs the following
actions:
- Displays the message, "Welcome to
W32.2faced," when first run.
- Makes continuous calls to the A: drive, so
the drive is always spinning.
- Adds the value:
"Microsoft
Corporation"="<Trojan path/file
name>"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Loads at startup as a System Tray icon that
looks like the Norton AntiVirus Auto-Protect
icon. If the icon is double-clicked, it will
display the message, "Are you Ready for
when Jesus comes?"
Clicking OK displays the message, "I
Am."
Trojan Visages Removal
Automatic Removal: Using BPS
Adware & Spyware Remover
to detect and remove Trojan.Visages AUTOMATICALLY!
Manual Removal:
Not Available.
Detection and Removal Instructions for Trojans
|