Spyware ( 0049bc961 )
Spyware ( 0049bc961 ) also known as Troj_Generic.UZOFV, TScope.Malware-Cryptor.SB, TROJ_GEN.R0CBC0UGK14. Malware Analysis of Spyware ( 0049bc961 ) – DMR.EXE Created files: %Program Files%\capicom.dll %Program Files%\dmr.exe %Program Files%\Sdmr.exe %SysDir%\capicom.dll Autostart registry keys: HKLM\Software\Classes\CLSID\{03ACC284-B757-4B8F-9951-86E600D2CD06}\InprocServer32\: “%SysDir%\capicom.dll” HKLM\Software\Classes\CLSID\{17E3A1C3-EA8A-4970-AF29-7F54610B1D4C}\InprocServer32\: “%SysDir%\capicom.dll” HKLM\Software\Classes\CLSID\{22A85CE1-F011-4231-B9E4-7E7A0438F71B}\InprocServer32\: “%SysDir%\capicom.dll” HKLM\Software\Classes\CLSID\{3605B612-C3CF-4ab4-A426-2D853391DB2E}\InprocServer32\: “%SysDir%\capicom.dll” HKLM\Software\Classes\CLSID\{54BA1E8F-818D-407F-949D-BAE1692C5C18}\InprocServer32\: “%SysDir%\capicom.dll” HKLM\Software\Classes\CLSID\{550C8FFB-4DC0-4756-828C-862E6D0AE74F}\InprocServer32\: “%SysDir%\capicom.dll” HKLM\Software\Classes\CLSID\{60A9863A-11FD-4080-850E-A8E184FC3A3C}\InprocServer32\: “%SysDir%\capicom.dll” HKLM\Software\Classes\CLSID\{65104D73-BA60-4160-A95A-4B4782E7AA62}\InprocServer32\: “%SysDir%\capicom.dll” HKLM\Software\Classes\CLSID\{78E61E52-0E57-4456-A2F2-517492BCBF8F}\InprocServer32\: “%SysDir%\capicom.dll” HKLM\Software\Classes\CLSID\{7BF3AC5C-CC84-429A-ACA5-74D916AD6B8C}\InprocServer32\: “%SysDir%\capicom.dll” HKLM\Software\Classes\CLSID\{8C3E4934-9FA4-4693-9253-A29A05F99186}\InprocServer32\: “%SysDir%\capicom.dll” HKLM\Software\Classes\CLSID\{9171C115-7DD9-46BA-B1E5-0ED50AFFC1B8}\InprocServer32\: “%SysDir%\capicom.dll”…