SPOOLS.EXE – Trojan Downloader

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SPOOLS.EXE – Trojan Downloader removal

FileMD5Virus Alias
SPOOLS.EXE 2e83e84d9763c867d96a2c2611e89672 Trojan Downloader
SPOOLS.EXE 2e83e84d9763c867d96a2c2611e89672 Trojan Adload
SPOOLS.EXE 2e83e84d9763c867d96a2c2611e89672 Worm Autorun
SPOOLS.EXE 2e83e84d9763c867d96a2c2611e89672 Trojan Agent
SPOOLS.EXE 2e83e84d9763c867d96a2c2611e89672 Trojan Small
SPOOLS.EXE 2e83e84d9763c867d96a2c2611e89672 Trojan ZBot

SPOOLS.EXE size: 544346 bytes
SPOOLS.EXE hash: 2E83E84D9763C867D96A2C2611E89672

Created files:

%UserProfile%\cftmon.exe
%SysDir%\drivers\spools.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ntuser: %WinDir%\System32\drivers\spools.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\autoload: %WinDir%\System32\config\Systemprofile\cftmon.exe
HKLM\System\CurrentControlSet\Services\Schedule\ImagePath: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C0064007200690076006500720073005C00730070006F006F006C0073002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ntuser: %WinDir%\System32\drivers\spools.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\autoload: %WinDir%\System32\config\Systemprofile\cftmon.exe

Detected by UnHackMe:

SPOOLS.EXE
Default location: %SYSDIR%\DRIVERS\SPOOLS.EXE

Dropper information:
MD5: 0878c6f85d8e34691d0f9343ef5eebcb
File size: 516882 bytes

Leave a Reply