Threat Database Trojans Trojan.Win32.Cosmu.xxs

Trojan.Win32.Cosmu.xxs

Trojan.Win32.Cosmu.xxs is a Windows platform Trojan program. Trojan.Win32.Cosmu.xxs is able to spread via spam e-mail and the exploitation of system vulnerabilities. On entering a system, Trojan.Win32.Cosmu.xxs will create a start-up registry entry and run in the background of the system. Trojan.Win32.Cosmu.xxs may also download additional infections and engage in malicious botnet activities.

File System Details

Trojan.Win32.Cosmu.xxs may create the following file(s):
# File Name Detections
1. %Temp%\Ev~NeN^e.eXe
2. %MyDocuments%\My Music .scr
3. %Windir%\AppPatch .scr
4. %Windir%\Connection Wizard .scr
5. %Windir%\dns .scr
6. %Windir%\Help .scr
7. %Windir%\java .scr
8. %Windir%\msagent .scr
9. %Windir%\Offline Web Pages .scr
10. %Windir%\Provisioning .scr
11. %Windir%\Resources .scr
12. %Windir%\srchasst .scr
13. %Windir%\system32 .scr
14. %Windir%\Web .scr
15. %MyDocuments%\My eBooks .scr
16. %Windir%\addins .scr
17. %Windir%\Config .scr
18. %Windir%\Debug .scr
19. %Windir%\ehome .scr
20. %Windir%\inf .scr
21. %Windir%\Microsoft.NET .scr
22. %Windir%\mui .scr
23. %Windir%\PeerNet .scr
24. %Windir%\repair .scr
25. %Windir%\SoftwareDistribution .scr
26. [file and pathname of the sample #1]
27. %Windir%\twain_32 .scr
28. %DesktopDir%\Unused Desktop Shortcuts .scr
29. %MyDocuments%\My Pictures .scr
30. %Windir%\Cache .scr
31. %Windir%\Cursors .scr
32. %Windir%\Driver Cache .scr
33. %Windir%\ime .scr
34. %Windir%\Media .scr
35. %Windir%\msapps .scr
36. %Windir%\pchealth .scr
37. %Windir%\Registration .scr
38. %Windir%\security .scr
39. %Windir%\system .scr
40. %Windir%\Temp .scr
41. %Windir%\WinSxS .scr

Registry Details

Trojan.Win32.Cosmu.xxs may create the following registry entry or registry entries:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

1 Comment

In awe of that answer! Really cool!

Trending

Most Viewed

Loading...