Threat Database Trojans Suspicious.Graybird.1

Suspicious.Graybird.1

Suspicious.Graybird.1 is a Trojan that may have been intentionally mutated or morphed by cyber-criminals. Suspicious.Graybird.1 may distribute itself via malicious websites or contaminated shareware. Suspicious.Graybird.1 may also be packed with a packer that hackers often add to malware in order to avoid detection or analysis. Suspicious.Graybird.1 should be promptly removed with an anti-spyware application.

File System Details

Suspicious.Graybird.1 may create the following file(s):
# File Name Detections
1. %Windir%\e7df.exe
2. %System%\7ds2.exe
3. %System%\hwqrgizey.dll
4. %System%\febb.dll
5. %System%\9dd1.dll
6. %Windir%\79e7.bmp
7. %Temp%\yjifh.htm
8. %System%\jedovbmt.dat
9. %Temp%\cml2A.tmp
10. %Favorites%\����֮��.url
11. %Windir%\92b7.flv
12. %Programs%\Internet Explorer.lnk
13. %DesktopDir%\����֮��.url
14. %Temp%\yvyfh.htm

Registry Details

Suspicious.Graybird.1 may create the following registry entry or registry entries:
[HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating\.Current]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
[HKEY_CURRENT_USER\Keyboard Layout\Preload]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden]

Trending

Most Viewed

Loading...