TrojanDownloader:Win32/Spycos.R

By ZulaZuza in Trojan Downloader | 10 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
More... More

TrojanDownloader:Win32/Spycos.R Description

TrojanDownloader:Win32/Spycos.R is Trojan that distributes and runs other computer infections by connecting to remote servers, usually via HTTP. TrojanDownloader:Win32/Spycos.R steals data about the compromised PC including anti-virus programs and online banking plugins installed on the computer, computer name, current user name, windows version of your computer and volume serial number of the hard disk. TrojanDownloader:Win32/Spycos.R transfers the information to the server ‘entreterimentoglass.com’. While being installed, TrojanDownloader:Win32/Spycos.R makes system modifications by adding possibly malevolent files however only when the default language on the computer is Portuguese. TrojanDownloader:Win32/Spycos.R blocks AVG and Avast security applications from normal functioning by ending processes and services of anti-virus programs if they exist on the PC. TrojanDownloader:Win32/Spycos.R creates copies of itself as a CPL file on the Temporary Files folder with a random 12-digit file name.

Type: Trojans

How Can You Detect TrojanDownloader:Win32/Spycos.R?

TrojanDownloader:Win32/Spycos.R Removal Details

TrojanDownloader:Win32/Spycos.R has typically the following processes in memory:

  • %Temp%\FXSAPIDebuglog.DLL

TrojanDownloader:Win32/Spycos.R creates the following files in the system:

  • %Temp%\_thundbs2.db

TrojanDownloader:Win32/Spycos.R creates the following registry entries:

  • HKEY_LOCAL_MACHINE\Software\Micrososft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}
  • HKEY_LOCAL_MACHINE\Software\Micrososft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run = “” = “%Temp%\”
  • HKEY_LOCAL_MACHINE\Software\Micrososft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}

Important Article Disclaimer

ESG Support Center

This entry was last updated on 10/17/12 and posted on 10/17/12. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Follow ESG

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.