Troj/CmjSpy-T

Category: Viruses and Spyware
Type: Trojan
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/CmjSpy-T is a backdoor Trojan.

Troj/CmjSpy-T copies itself to the Windows system folder with the filename HPSERVER.EXE and then sets itself to run on system startup either by creating a service with a Service Name and Display Name of "HpPrinter" or by setting a value in the registry at the following location:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HpPrinter

Troj/CmjSpy-T attempts to drop a data file FIRSTRUNMAGIC.TXT to the Windows temp folder.

Troj/CmjSpy-T may attempt to drop and run files to the Windows system folder including the file M2SYADLL.DLL, also detected as Troj/CmjSpy-T. Troj/CmjSpy-T may attempt to inject this DLL into EXPLORER.EXE.

Troj/CmjSpy-T may act as a backdoor Trojan performing tasks including attempting to send and receive information from websites, downloading and executing further files, monitoring user's keystrokes and sending emails from the infected computer.

download Try Sophos products for free
Download now