Home Malware Programs Downloaders Win32/Hopee

Win32/Hopee

Posted: November 26, 2008

Win32/Hopee is a Trojan downloader that secretly enters your computer due to weaknesses or vulnerabilities in your system. The Win32/Hopee Trojan downloader communicates with a remote web server so it can send information to hackers making you susceptible to identity theft and financial loss.

Win32/Hopee modifies Windows registry to load the Trojan on every startup. Win32/Hopee also may disable already installed security software and produce annoying pop up ads as well as install additional malware onto your PC.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\[RANDOM LETTERS]>.syz
    2 %System%\cssrss.exe
    3 %System%\nso12k.sys

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\WMDM PMSP Service = "%System%\cssrss.exe"
Loading...