Home Malware Programs Trojans Trojan.Win32.Genome.eggw

Trojan.Win32.Genome.eggw

Posted: March 17, 2011

Trojan.Win32.Genome.eggw is a malicious computer trojan that makes changes to system files and blocks a user trying to access security websites without his/her knowledge. Trojan.Win32.Genome.eggw will propagate via instant messaging programs and has another payload of downloading and performing variants of W32.Spybot.Worm on a targeted computer. Trojan.Win32.Genome.eggw includes features of an identified security risk that runs automatically when Windows starts. Trojan.Win32.Genome.eggw involves a backdoor functionality that enables unauthorized access and control of a corrupted system.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\SpyTraffic\lang\help_rus.chm
    2 %ProgramFiles%\SpyTraffic\lang\lang_changes.txt
    3 %Programs%\SpyTraffic\Spy Traffic on the Web.lnk
    4 %Programs%\SpyTraffic\Spy Traffic.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\CrazyHOMEHKEY_LOCAL_MACHINE\SOFTWARE\CrazyHOME\Spy TrafficHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SpyTraffic
Loading...