SPOOLS.EXE – Trojan Downloader

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

SPOOLS.EXE – Trojan Downloader removal

FileMD5Virus Alias
SPOOLS.EXE 849a74cff23beb58ab3d7356b12ab9ec Trojan Downloader
SPOOLS.EXE 849a74cff23beb58ab3d7356b12ab9ec Trojan Adload
SPOOLS.EXE 849a74cff23beb58ab3d7356b12ab9ec Worm Autorun
SPOOLS.EXE 849a74cff23beb58ab3d7356b12ab9ec Trojan Agent
SPOOLS.EXE 849a74cff23beb58ab3d7356b12ab9ec Trojan Small
SPOOLS.EXE 849a74cff23beb58ab3d7356b12ab9ec Trojan ZBot

SPOOLS.EXE size: 540004 bytes
SPOOLS.EXE hash: 849A74CFF23BEB58AB3D7356B12AB9EC

Created files:

%UserProfile%\cftmon.exe
%SysDir%\drivers\spools.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ntuser: %WinDir%\System32\drivers\spools.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\autoload: %WinDir%\System32\config\Systemprofile\cftmon.exe
HKLM\System\CurrentControlSet\Services\Schedule\ImagePath: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C0064007200690076006500720073005C00730070006F006F006C0073002E006500780065000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ntuser: %WinDir%\System32\drivers\spools.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\autoload: %WinDir%\System32\config\Systemprofile\cftmon.exe

Detected by UnHackMe:

SPOOLS.EXE
Default location: %SYSDIR%\DRIVERS\SPOOLS.EXE

Dropper information:
MD5: 0c357265eaed7bdaaa82258d5bdc59f0
File size: 512540 bytes

Leave a Reply