Threat Database Trojans Spammer:Win32/Tedroo.C

Spammer:Win32/Tedroo.C

By ESGI Advisor in Trojans

Spammer:Win32/Tedroo.C is a computer Trojan parasite that may open up a system to a remote source where a hacker could steal valuable information. Spammer:Win32/Tedroo.C may also send out emails to other systems without the computer users consent where the messages include scraped data from the infected computer. Malicious websites may also be loaded on a system infected with Spammer:Win32/Tedroo.C potentially leading computer users to additional malware. Detection and removal of Spammer:Win32/Tedroo.C is essential to prevent further infection or theft of stored data.

File System Details

Spammer:Win32/Tedroo.C may create the following file(s):
# File Name Detections
1. %AllUsersProfile%\Application Data\.exe
2. %AllUsersProfile%\Application Data\.dll
3. %UserProfile%\Desktop\Spammer:Win32/Tedroo.C.lnk
4. %UserProfile%\Start Menu\Programs\Spammer:Win32/Tedroo.C\Spammer:Win32/Tedroo.C.lnk
5. %AllUsersProfile%\Application Data\
6. %UserProfile%\Start Menu\Programs\Spammer:Win32/Tedroo.C\Uninstall Spammer:Win32/Tedroo.C.lnk
7. %AllUsersProfile%\Application Data\~r
8. %UserProfile%\Start Menu\Programs\Spammer:Win32/Tedroo.C\

Registry Details

Spammer:Win32/Tedroo.C may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'yes'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ".exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = 0'

Trending

Most Viewed

Loading...