Home Malware Programs Trojans Spammer:Win32/Tedroo.C

Spammer:Win32/Tedroo.C

Posted: July 28, 2011

Spammer:Win32/Tedroo.C is a variant of the Spammer.Tedroo Trojan that uses your computer's resources to send spam email to online mailboxes. Many Spammer:Win32/Tedroo.C infections coincide with affiliated Trojan and virus infections, and Spammer:Win32/Tedroo.C may also be used to engage in other attacks, such as creating security vulnerabilities in your PC or installing other malicious programs, including spyware or rogue security products. Spammer:Win32/Tedroo.C infections may not show any obvious symptoms, and you should use a good security program to find and delete Spammer:Win32/Tedroo.C, before any serious damage occurs.

Spammer:Win32/Tedroo.C, the Invisible Spam-Sender

Early Spammer:Win32/Tedroo.C infections were seen as long ago as 2007, but Spammer:Win32/Tedroo.C and other variants of the Tedroo Trojan family are still in circulation and can pose a threat to any computer that they infect. Trojans that are similar to Spammer:Win32/Tedroo.C have been circulated through fake media updates and abusive Flash and Java scripts, both of which use false pretenses to install Spammer:Win32/Tedroo.C, sometimes without your consent.

Just as its infection method is hidden, Spammer:Win32/Tedroo.C's varied attacks are also concealed to prevent you from catching Spammer:Win32/Tedroo.C in the act. Spammer:Win32/Tedroo.C will use the Windows Registry to run without permission, and rootkit-based methods to infect the native explorer.exe memory process.

After this, our SpywareRemove.com malware researchers found that Spammer:Win32/Tedroo.C, like other members of the Tedroo spammer family, uses the infected computer's resources to send repeated spam messages. Since this takes place with the assistance of a built-in SMTP client engine, you will not see these messages in online mailbox. Spammer:Win32/Tedroo.C may harvest your contacts for addresses to spam or spoof your sender name, to make it look as though the spam is being sent from your address.

The Non-Spam Weaponry That Spammer:Win32/Tedroo.C Wields

Spammer:Win32/Tedroo.C doesn't confine itself to spamming mailboxes, however. SpywareRemove.com malware analysts have also seen Spammer:Win32/Tedroo.C engaged in a behavior that's very similar to that of a standard backdoor Trojan. Backdoor Trojans attack your security settings and programs to make your PC vulnerable to other threats, including criminal remote control. If you suspect that you have a Spammer:Win32/Tedroo.C infection or a similar backdoor Trojan on your PC, you may wish to check your network activity, ports settings and other network-related features for tampering.

Another minor sign of a possible Spammer:Win32/Tedroo.C infection is the excessive use of system resources, especially memory. Remember that this memory usage will be attached to the normal processes that Spammer:Win32/Tedroo.C has infected and check your explorer.exe process for unusually high memory expenditure.

Spammer:Win32/Tedroo.C may also come with other infections, especially fellow Trojans. Some of the malicious programs that have been seen with Spammer:Win32/Tedroo.C include Trojan.Win32.Agent.asu, VirTool:WinNT/Smallrk.F and Win-Trojan/Rootkit.7923. You can delete Spammer:Win32/Tedroo.C and the other PC threats mentioned above, by using a suitable anti-virus or security scanner, ideally in Safe Mode.

Loading...