Home Malware Programs Trojans Trojan.Win32.Refroso.ejh

Trojan.Win32.Refroso.ejh

Posted: October 30, 2009

Trojan.Win32.Refroso.ejh is a Trojan horse that presents a high security risk for the compromised system and/or its network environment. Trojan.Win32.Refroso.ejh can disguise itself as a Yahoo Emoticons generator to monitor running applications on infected computers. Trojan.Win32.Refroso.ejh attempts to steal personal information and sends them to the hacker. Trojan.Win32.Refroso.ejh also serves as a backdoor Trojan so that the hacker can obtain illegal access to the affected computer. Trojan.Win32.Refroso.ejh should be dealt with ruthlessly by removal without delay.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %CommonPrograms%\Power Of Silence 1.9
    2 %CommonPrograms%\Power Of Silence 1.9\Power Of Silence 1.9 on the Web.url
    3 %CommonPrograms%\Power Of Silence 1.9\Power Of Silence 1.9.lnk
    4 %CommonPrograms%\Power Of Silence 1.9\Uninstall Power Of Silence 1.9.lnk
    5 %ProgramFiles%\Power Of Silence 1.9
    6 %ProgramFiles%\Power Of Silence 1.9\picclp32.ocx
    7 %ProgramFiles%\Power Of Silence 1.9\Power Of silence 1.9.exe
    8 %ProgramFiles%\Power Of Silence 1.9\SafeList.txt
    9 %ProgramFiles%\Power Of Silence 1.9\trueSpeech.ocx
    10 %ProgramFiles%\Power Of Silence 1.9\unins000.dat
    11 %ProgramFiles%\Power Of Silence 1.9\unins000.exe
    12 %ProgramFiles%\Power Of Silence 1.9\yacscom.dll
    13 %ProgramFiles%\Power Of Silence 1.9\YMSG12ENCRYPT.dll
    14 %Temp%\is-ED6FP.tmp
    15 %Temp%\is-ED6FP.tmp\_isetup
    16 %Temp%\is-ED6FP.tmp\_isetup\_RegDLL.tmp
    17 %Temp%\is-ED6FP.tmp\_isetup\_shfoldr.dll
    18 %Temp%\is-I60GH.tmp
    19 %Temp%\is-I60GH.tmp\POWERO~1.tmp
    20 %Temp%\IXP000.TMP
    21 %Temp%\IXP000.TMP\1.exe
    22 %Temp%\IXP000.TMP\POWERO~1.EXE

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Power Of Silence 1.9_is1
Loading...