SPOOLS.EXE – Trojan Downloader

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SPOOLS.EXE – Trojan Downloader removal

FileMD5Virus Alias
SPOOLS.EXE 5550127c32ca6b740968c07591a9955e Trojan Downloader
SPOOLS.EXE 5550127c32ca6b740968c07591a9955e Trojan Adload
SPOOLS.EXE 5550127c32ca6b740968c07591a9955e Worm Autorun
SPOOLS.EXE 5550127c32ca6b740968c07591a9955e Trojan Agent
SPOOLS.EXE 5550127c32ca6b740968c07591a9955e Trojan Small
SPOOLS.EXE 5550127c32ca6b740968c07591a9955e Trojan ZBot

SPOOLS.EXE size: 521656 bytes
SPOOLS.EXE hash: 5550127C32CA6B740968C07591A9955E

Created files:

%UserProfile%\cftmon.exe
%SysDir%\drivers\spools.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ntuser: %WinDir%\System32\drivers\spools.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\autoload: %WinDir%\System32\config\Systemprofile\cftmon.exe
HKLM\System\CurrentControlSet\Services\Schedule\ImagePath: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C0064007200690076006500720073005C00730070006F006F006C0073002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ntuser: %WinDir%\System32\drivers\spools.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\autoload: %WinDir%\System32\config\Systemprofile\cftmon.exe

Detected by UnHackMe:

SPOOLS.EXE
Default location: %SYSDIR%\DRIVERS\SPOOLS.EXE

Dropper information:
MD5: 08afee20a3bb959116d86fdcf265836d
File size: 494192 bytes

Leave a Reply