Home Malware Programs Trojans Win32/Gys.A Trojan

Win32/Gys.A Trojan

Posted: April 9, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 576
First Seen: April 9, 2013
Last Seen: May 4, 2023
OS(es) Affected: Windows

Win32/Gys.A Trojan is a Trojan that spreads via a spam email message. The spam email that infects vulnerable PCs with Win32/Gys.A Trojan has the subject 'Your private photos are there for anyone to see. why??'. The fake email message contains the attachment, which is a ZIP archive named 'EPS00348.zip'. The archive contains an executable file named 'EPS00348.exe'. The icon of the malicious file looks like a very nice picture of nature; Green grass and blue sky, which most likely were created in order to confuse and/or steal the affected PC user's attention. The file is detected as Win32/Gys.A Trojan.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



EPS00348.zip File name: EPS00348.zip
Mime Type: unknown/zip
Group: Malware file
EPS00348.exe File name: EPS00348.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SunJavaUpdateSched” = "C:\Documents and Settings\All Users\svchost.exe"

Additional Information

The following messages's were detected:
# Message
1Sorry to disturb you. Someone sent me thee pictures they seem to be from you and your boyfriend I'm really troubled by this why do you send your private naked photos around?? this is beyound my understanding. It's in attachment.

Loading...