Threat Database Trojans Win32/Gys.A Trojan

Win32/Gys.A Trojan

By Domesticus in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 246
First Seen: April 9, 2013
Last Seen: May 4, 2023
OS(es) Affected: Windows

Win32/Gys.A Trojan is a Trojan that is distributed via a spam email. The unsolicited email message that affects targeted computers with Win32/Gys.A Trojan carries the subject 'Your private photos are there for anyone to see. why??'. The bogus email message includes the attachment, which is a ZIP archive called 'EPS00348.zip'. The archive includes an executable file called 'EPS00348.exe'. The icon of the malevolent file seems to be a very nice nature image: green grass and blue sky, which most probably were generated in order to mislead and/or steal the victimized computer owner's attention. The malevolent file is found as Win32/Gys.A Trojan.

File System Details

Win32/Gys.A Trojan may create the following file(s):
# File Name Detections
1. EPS00348.exe
2. EPS00348.zip

Registry Details

Win32/Gys.A Trojan may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SunJavaUpdateSched” = "C:\Documents and Settings\All Users\svchost.exe"

Trending

Most Viewed

Loading...