SPOOLS.EXE – Trojan Downloader

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SPOOLS.EXE – Trojan Downloader removal

FileMD5Virus Alias
SPOOLS.EXE 666dcf84e4658ca7fc8ef5e8922a73dc Trojan Downloader
SPOOLS.EXE 666dcf84e4658ca7fc8ef5e8922a73dc Trojan Adload
SPOOLS.EXE 666dcf84e4658ca7fc8ef5e8922a73dc Worm Autorun
SPOOLS.EXE 666dcf84e4658ca7fc8ef5e8922a73dc Trojan Agent
SPOOLS.EXE 666dcf84e4658ca7fc8ef5e8922a73dc Trojan Small
SPOOLS.EXE 666dcf84e4658ca7fc8ef5e8922a73dc Trojan ZBot

SPOOLS.EXE size: 463250 bytes
SPOOLS.EXE hash: 666DCF84E4658CA7FC8EF5E8922A73DC

Created files:

%UserProfile%\cftmon.exe
%SysDir%\drivers\spools.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ntuser: %WinDir%\System32\drivers\spools.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\autoload: %WinDir%\System32\config\Systemprofile\cftmon.exe
HKLM\System\CurrentControlSet\Services\Schedule\ImagePath: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C0064007200690076006500720073005C00730070006F006F006C0073002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ntuser: %WinDir%\System32\drivers\spools.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\autoload: %WinDir%\System32\config\Systemprofile\cftmon.exe

Detected by UnHackMe:

SPOOLS.EXE
Default location: %SYSDIR%\DRIVERS\SPOOLS.EXE

Dropper information:
MD5: 1633ecd932ef080f1c662ec86522fe0b
File size: 435786 bytes

Leave a Reply