Zendown.Trojan

Discovered:
March 20, 2002
Updated:
February 13, 2007 12:11:39 PM
Also Known As:
Trojan/IHateYou, Trojan.Win32.Hatu
Type:
Trojan Horse

When it is executed, Zendown.Trojan creates the file C:\WINDOWS\ihateyou.exe

and adds the values:

Shutdown C:\Windows\ihateyou.exe
Shutdown2 C:\Windows\rundll32.exe shell32,SHExitWindowsEx 1

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

The Trojan then shuts down Windows.

The values that it added to the registry will run each time that you start Windows, and, when run, they immediately shut down Windows, preventing you from using the computer in normal mode.

Antivirus Protection Dates

  • Initial Rapid Release version March 20, 2002
  • Latest Rapid Release version June 22, 2009 revision 066
  • Initial Daily Certified version March 20, 2002
  • Latest Daily Certified version June 19, 2009 revision 051
  • Initial Weekly Certified release date March 20, 2002
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Eric Chien

Search Threats

Search by name

Example: W32.Beagle.AG@mm
ThreatCon Widget
Internet Security Threat Report, Volume 16
Symantec DeepSight Screensaver