Home Malware Programs Trojans Trojan.Spyeyes

Trojan.Spyeyes

Posted: May 5, 2011

Trojan.Spyeyes is a ransomware Trojan that prevents the use of your computer and displays a pornographic image until you remove Trojan.Spyeyes or use a purchasable unlock code. Since Trojan.Spyeyes is produced by a toolkit that can be reused and reconfigured by multiple criminals, new versions of Trojan.Spyeyes may show slightly different structural characteristics or infect your PC in different ways. Instead of purchasing a code to unlock Trojan.Spyeyes, it's strongly recommended that you use advanced anti-malware tactics and software to remove Trojan.Spyeyes to get your computer back to normal.

From a Backdoor Spy to a Ransomer

SpyEye Trojans like Trojan.Spyeyes are created by a prefabricated software toolkit that different criminals can use to create various types of Trojans, including Trojan.Spyeyes. Earlier versions of these Trojans exhibited other characteristics, such as being spyware and limiting attacks to security applications, but the newer Trojan.Spyeyes variant is ransomware that locks up your computer.

Once your PC is infected, Trojan.Spyeyes will prevent all significant use of applications or system functions. To add insult to injury, Trojan.Spyeyes will even display an x-rated image to give you cause to panic.

You may also see a message about supposed illegal activities on your computer or the potential intervention of law enforcement, but these simple ruses should be ignored. Obviously, law enforcement will never use a Trojan like Trojan.Spyeyes to lock up your PC if they suspect you of conducting illegal activities, and they certainly will not offer you the simple payment solution that Trojan.Spyeyes offers for a fast way out.

Don't Take Trojan.Spyeyes's Way Out of the Problem That Trojan.Spyeyes Caused

Trojan.Spyeyes offers you the ability to procure a code to unlock your PC, but only if you send an SMS message to a premium number. Besides giving criminals money, this will only attack the symptom rather than the problem itself, which is Trojan.Spyeyes. You should avoid doing this and, if necessary, dispute any such charges.

Although Trojan.Spyeyes may randomize Trojan.Spyeyes's name and location, there are some files that are known to be related to Trojan.Spyeyes and similar Trojans:

  • empsys.exe
  • dyfhiushduh.exe
  • fheydbueyj.exe
  • xgukxzrvux.exe
  • cleansweep.exe
  • syscheckrt.exe

Different brands of anti-malware programs will detect Trojan.Spyeyes by different names, such as PWS-Zbot.gen.br, TROJ_MEREDROP.QK, Win32/Hexzone.BG, Win-Trojan/Spyeyes.175104, Win32/LockScreen.UK, Trojan-Spy.Win32.SpyEyes.yu, Infostealer and Win32.Calelk.C.

Working around Trojan.Spyeyes's system-freezing attack may require you to use Safe Mode or boot your computer from a removable device. If Trojan.Spyeyes will not let you download necessary anti-malware files to remove Trojan.Spyeyes, then rename the files into generic ones like explorer.exe or iexplore.exe. Typically this will let you finish the download and run the program so that you can delete Trojan.Spyeyes in a simple system scan.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 c:\documents and settings\administrator\local settings\temp\tempsys.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit=\userinit.exe,c:\docume~1\admini~1\locals~1\temp\tempsys.exe[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1][HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3][HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4][HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0][HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1][HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2][HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3][HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4]
Loading...