Home Malware Programs Trojans Trojan.Win32.Spy2

Trojan.Win32.Spy2

Posted: May 2, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 96
First Seen: May 2, 2013
Last Seen: December 13, 2023
OS(es) Affected: Windows

Trojan.Win32.Spy2 is a deceptive Trojan that may enter into a system through a drive-by download or malicious file. After installed, Trojan.Win32.Spy2 may run in the background to avoid being detected or removed. A remote attacker may gain access to a system infected by Trojan.Win32.Spy2 where they may obtain personal information from that system’s hard drive. It is essential that the appropriate actions be taken to completely remove Trojan.Win32.Spy2 from your computer.

Aliases

Trj/CI.A [Panda]Generic32.CDAA [AVG]Trojan.Win32.Spy2 [Ikarus]Trojan/Win32.Agent [AhnLab-V3]TR/Kazy.6132.11 [AntiVir]TrojWare.Win32.Trojan.Agent.Gen [Comodo]Trojan-Dropper.Win32.Injector.idne [Kaspersky]WS.Reputation.1 [Symantec]Artemis!F5D3AE735E53 [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\AppleDev0\safpdndnn.exe File name: safpdndnn.exe
Size: 610.3 KB (610304 bytes)
MD5: f5d3ae735e539df02aba05875e3c14e2
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\AppleDev0
Group: Malware file
Last Updated: May 13, 2013
%CommonAppData%\windowviewcon\11st.ico File name: %CommonAppData%\windowviewcon\11st.ico
Mime Type: unknown/ico
Group: Malware file
%CommonAppData%\WindowsPurchaseHelper\windowsphup.exe File name: %CommonAppData%\WindowsPurchaseHelper\windowsphup.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%CommonAppData%\WindowsPurchaseHelper\windowsph.exe File name: %CommonAppData%\WindowsPurchaseHelper\windowsph.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%CommonAppData%\windowviewcon\11[4 RANDOM CHARACTERS].lnk File name: %CommonAppData%\windowviewcon\11[4 RANDOM CHARACTERS].lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%CommonAppData%\windowviewcon\auction.ico File name: %CommonAppData%\windowviewcon\auction.ico
Mime Type: unknown/ico
Group: Malware file
%CommonAppData%\windowviewcon\config.cfg File name: %CommonAppData%\windowviewcon\config.cfg
Mime Type: unknown/cfg
Group: Malware file
%CommonAppData%\windowviewcon\gmarket.ico File name: %CommonAppData%\windowviewcon\gmarket.ico
Mime Type: unknown/ico
Group: Malware file
%CommonAppData%\windowviewcon\windowviewcon.exe File name: %CommonAppData%\windowviewcon\windowviewcon.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%CommonAppData%\windowviewcon\windowviewconup.exe File name: %CommonAppData%\windowviewcon\windowviewconup.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%CommonAppData%\windowviewcon\[4 RANDOM CHARACTERS].lnk File name: %CommonAppData%\windowviewcon\[4 RANDOM CHARACTERS].lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%Temp%\WindowviewconSetup_clickkoreav.exe File name: %Temp%\WindowviewconSetup_clickkoreav.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\WindowsPurchaseHelperSetup_clickkorear.exe File name: %Temp%\WindowsPurchaseHelperSetup_clickkorear.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%DesktopDir%\Internet Explorer.lnk File name: %DesktopDir%\Internet Explorer.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{CLSID Path}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{8605E9B4-68C1-4ED9-B282-74C1AA3C312E}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{D64A7743-7E62-4002-90EA-80E0671F9902}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{FA214B13-1A9F-480B-B749-94A566FC59D9}HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\UninstallHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\WindowsPurchaseHelperHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\windowviewconHKEY_CURRENT_USER\Software\WindowsPurchaseHelperHKEY_CURRENT_USER\Software\WindowsPurchaseHelper\filesHKEY_CURRENT_USER\Software\windowviewconbHKEY_CURRENT_USER\Software\windowviewconb\FILES
Loading...