The file spooldr.sys damages the stability of integral processes necessary for MS Windows OS versions to run properly. The spooldr.sys infects computers running on MS Windows by making use of the Trojan.Packed.13 malware application.
The Trojan.Packed.13 is a malicious process that is distributed through spam known as Peacomm. The Peacomm spam convinces its recipients to navigate their browsers to a website with an applet.exe link. The site also executes a JavaScript routine that embeds a process which exploits a WMP vulnerability. The WMP vulnerability is exploited by the JavaScript routine after users cancel access to a "Secure Login Applet" that is launched upon visiting the website.
At this point, a successful exploitation of the WMP vulnerability will initialize the download of a small process to the compromised machine. The small process then executes the download and subsequent initialization of the applet.exe on the MS Windows-based machine. Both of these malicious applications are known as Trojan.Packed.13.
Afterwards, the execution of applet.exe is initialized. This allows it to produce a copy of itself that is dropped to the Windows folder of the system partition as spooldr.exe. This in turn provides the malware process with the capability to deploy a kernel driver known as spooldr.sys, which is dropped to the System folder of the MS Windows partition. The spooldr.sys then initializes the execution of the spooldr.exe file by making use of a process similar to a shellcode routine on MS Windows Explorer.
Sunday,Apr19,
Sunday,
Apr
19,
What is spooldr.sys?
tags: windows system | author: chaoPosts Relacionados:
- How to disable Aero Shake in Windows 7
- How to Install Windows Vista from a USB Hard Drive
- How to Install Windows Vista From a Portable Hard Drive
- How to Clear the Command Window Screen?
- How to Get Yahoo DSL to Work With Vista
- How to Undelete and Recover Deleted Files From Windows Operating System
- How to Retrieve Lost Information Following an HP PC System Recovery
- Win 7 shipping at “holiday season,” Win Server 2008 R2 beta available
- How to Get the Most Out of Windows Vista Speech Recognition
- How to disable Aero Peek in Windows 7
Subscribe to:
Post Comments (Atom)
0 comment:
Post a Comment