SPOOLS.EXE – Trojan Downloader

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SPOOLS.EXE – Trojan Downloader removal

FileMD5Virus Alias
SPOOLS.EXE b8942879b4db43186419b49ffd98a037 Trojan Downloader
SPOOLS.EXE b8942879b4db43186419b49ffd98a037 Trojan Adload
SPOOLS.EXE b8942879b4db43186419b49ffd98a037 Worm Autorun
SPOOLS.EXE b8942879b4db43186419b49ffd98a037 Trojan Agent
SPOOLS.EXE b8942879b4db43186419b49ffd98a037 Trojan Small
SPOOLS.EXE b8942879b4db43186419b49ffd98a037 Trojan ZBot

SPOOLS.EXE size: 548688 bytes
SPOOLS.EXE hash: B8942879B4DB43186419B49FFD98A037

Created files:

%UserProfile%\cftmon.exe
%SysDir%\drivers\spools.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ntuser: %WinDir%\System32\drivers\spools.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\autoload: %WinDir%\System32\config\Systemprofile\cftmon.exe
HKLM\System\CurrentControlSet\Services\Schedule\ImagePath: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C0064007200690076006500720073005C00730070006F006F006C0073002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ntuser: %WinDir%\System32\drivers\spools.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\autoload: %WinDir%\System32\config\Systemprofile\cftmon.exe

Detected by UnHackMe:

SPOOLS.EXE
Default location: %SYSDIR%\DRIVERS\SPOOLS.EXE

Dropper information:
MD5: 09ba161f528ebae9ec0f23d383dd5767
File size: 521224 bytes

Leave a Reply