If your computer has not been protected with anti-virus software and has been infected with malware, you will need to take the following actions to delete this:
- Using Task Manager end the "duospeak.exe" process.
- Delete the original trojan file (its location on the infected computer will depend on how the program got onto the computer).
- Run a full Kaspersky Antivirus scan of the computer with updated antivirus databases (download trial version).
After launching, the malicious library checks the name of the process in the address space loaded. With the "duospeak.exe" process loaded into the address space, the trojan allows for tracking of the information entered by the user into the windows with the following class names:
YYMainWnd YYLogin Edit
and sends the data received to the attacker's server in HTML-requests:
A trojan program designed to steal the user's authentication data. It is a Windows dynamic-link library (PE-DLL file). 4608 bytes. Written in C++.