Sophos

Troj/Spyre-B

Aliases
  • Trojan.Win32.TopAntiSpyware.i
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 6 April 2005 20:41:19 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/Spyre-B is Trojan for the Windows platform.

Troj/Spyre-B will create an HTML file named DESKTOP.HTML in a folder named Web in the Windows folder. Troj/Spyre-B will set this file as the Windows Desktop background.

Troj/Spyre-B may attempt to change the browser settings for Java and open a web page. Troj/Spyre-B may attempt to download and run further executables.

Troj/Spyre-B consists of the following three files:

<Windows system folder>\srpcsrv32.dll
<Windows system folder>\txfdb32.dll
<Windows system folder>\spoolsrv32.exe

In order to run automatically, Troj/Spyre-B may set one of the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
Srv32 spool service
<Windows system folder>\spoolsrv32.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
Srv32 spool service
<Windows system folder>\spoolsrv32.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer