Home Malware Programs Trojans Trojan.Reconyc

Trojan.Reconyc

Posted: June 17, 2015

Threat Metric

Threat Level: 8/10
Infected PCs: 7,157
First Seen: June 28, 2014
Last Seen: May 29, 2023
OS(es) Affected: Windows

Trojan.Reconyc is a versatile threat that can leave your computer in a severely hindered state. Depending on its masters will, Trojan.Reconyc is capable of many things, none of which pleasant. Trojan.Reconyc is primarily distributed through spam emails and drive-by downloads. Trojan.Reconyc can limit the computer functionality; for instance, Trojan.Reconyc may prevent access to the Windows Registry, Task Manager, Command Prompts and other essential system tools. Furthermore, Trojan.Reconyc is capable of connecting to its remote C&C (Command and & Control) center, with a communication bridge working both ways. Trojan.Reconyc may send vital information about your computer, or it can receive instructions from its malevolent overlords. Trojan.Reconyc is a dangerous computer infection whose propagation should be prevented at all costs. To combat Trojan.Reconyc and its ilk, it is imperative to have an adequate and robust anti-virus solution. A good anti-malware application will drastically minimize the chance of infection by Trojan.Reconyc, or any other malware for that matter.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Roaming\svchost.exe File name: svchost.exe
Size: 141.66 KB (141666 bytes)
MD5: 82f0b083c3f14c7d6761fbffc88e714c
Detection count: 548
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\svchost.exe
Group: Malware file
Last Updated: February 1, 2023
C:\Users\<username>\AppData\Local\Temp\KB03585760.exe File name: KB03585760.exe
Size: 131.07 KB (131072 bytes)
MD5: bf63d2dc2cadb492c132db51723118ba
Detection count: 272
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\KB03585760.exe
Group: Malware file
Last Updated: May 29, 2023
%APPDATA%\rundll3.exe File name: rundll3.exe
Size: 118.78 KB (118784 bytes)
MD5: f80c8320b21a651a2845e3f9d5b72c59
Detection count: 162
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: March 21, 2017
f3e9d4253abd19a82e4175349a92f55cce8c227cda195faa7b9570a479d48d63.exe File name: f3e9d4253abd19a82e4175349a92f55cce8c227cda195faa7b9570a479d48d63.exe
Size: 147.96 KB (147968 bytes)
MD5: 8f2b3fd3dc239e9f9cd173928d6f4720
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 26, 2016
f2218d4c720c133514ffb5cbf54a9654230c8e6fbf530b7333a1cb34bd3592a8.exe File name: f2218d4c720c133514ffb5cbf54a9654230c8e6fbf530b7333a1cb34bd3592a8.exe
Size: 348.16 KB (348160 bytes)
MD5: f5115eb6262a9e5bfbee5302326e6200
Detection count: 41
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 26, 2016
%WINDIR%\system32\rundll3.exe File name: rundll3.exe
Size: 182.62 KB (182626 bytes)
MD5: ee120e33367f0daa3ebd17cb5e5d439d
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: March 21, 2017
%APPDATA%\rundll3.exe File name: rundll3.exe
Size: 221.18 KB (221184 bytes)
MD5: 0f3aab20348c9a57d11b80ea61105710
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: March 21, 2017
%APPDATA%\rundll3.exe File name: rundll3.exe
Size: 125.43 KB (125436 bytes)
MD5: 38308688f8489311f9005d857f755dc7
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: March 21, 2017
%APPDATA%\rundll3.exe File name: rundll3.exe
Size: 147.45 KB (147456 bytes)
MD5: b10a060618d5140804f7aa9def50f824
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: March 21, 2017
%WINDIR%\system32\rundll3.exe File name: rundll3.exe
Size: 235.87 KB (235874 bytes)
MD5: d574fb202f4083e417b68eabb2ec38a7
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: March 21, 2017
%LOCALAPPDATA%\Domain\AppConfig.exe File name: AppConfig.exe
Size: 166.4 KB (166400 bytes)
MD5: 80e12239f25e6532458dac9a433e30f9
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Domain
Group: Malware file
Last Updated: April 28, 2017
9acdccfb03937545dccd2a54a99647c808e57655df2036d5e974662af31f2fb5.exe File name: 9acdccfb03937545dccd2a54a99647c808e57655df2036d5e974662af31f2fb5.exe
Size: 5.93 MB (5937104 bytes)
MD5: 4fac9bfabe264552777634a888150b1b
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 26, 2016
%APPDATA%\rundll3.exe File name: rundll3.exe
Size: 200.7 KB (200704 bytes)
MD5: ba5486655e426b1e50e60bca9ccaee2c
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: March 21, 2017
%APPDATA%\rundll3.exe File name: rundll3.exe
Size: 131.07 KB (131072 bytes)
MD5: 6395098a4385ba0a72dd5d445c494a52
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: March 21, 2017
%WINDIR%\system32\rundll3.exe File name: rundll3.exe
Size: 196.6 KB (196608 bytes)
MD5: 4f87781340b11d16aaa3e0fdd4fbcaae
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: March 21, 2017
file.exe File name: file.exe
Size: 49.15 KB (49152 bytes)
MD5: 59c72381567d233d36b732a07e7858e5
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 29, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%ALLUSERSPROFILE%\wininit.exe%WINDIR%\System32\rundll3.exe
Loading...