Sophos

Troj/Spyre-A

Aliases
  • Trojan-Dropper.Win32.Xaw.b
  • TrojanClicker.Win32.Spyre.b
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 22 December 2004 22:03:02 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for removing Trojans.

In order to remove the Trojan:
rename the infected DLL file, eg. by changing the extension
reboot the computer
delete both files (the EXE and the renamed DLL)
restore the previous backdrop
delete the advertisement HTML fil

More Information

Troj/Spyre-A is an advertising Trojan.

In order to run automatically when Windows starts up the Trojan repeatedly creates the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\
"Srv32 spool service"
"C:\Windows\System32\runsrv32.exe"

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\
"Srv32 spool service"
"C:\Windows\System32\runsrv32.exe"

Troj/Spyre-A creates an HTML file in C:\Windows\Web\ and makes this file the wallpaper. This file usually contains an advertisement.

The Trojan comes in two files, usually named
runsrv32.exe - starts the Trojan after login
runsrv32.dll - injected into the explorer.exe process

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer