TeleDesktop
|
Description:
|
Spyware
|
|
Risk Level:
|
Low
|
|
Date of First Occurence:
|
Tuesday, May 06, 2008
|
|
Software Developer:
|
(unknown)
|
|
Brief Info:
|
Spyware is computer software that is installed surreptitiously on a personal computer to intercept or take partial control over the user's interaction with the computer, without the user's informed consent.
|
|
Removal:
|
This threat can be removed using "Spyware
Terminator"
|
ENTFERNEN SPYWARE »
Geographical Distribution of Threat "TeleDesktop"
Threat Info
View All
Detected Items
- Detected Files:
%PROGRAMFILES%\PotomacSoft\TeleDesktop\ptinstass.dll
MD5: 4248503F9F6DFEDDBFC42DE5CB990C72 Size:24576
MD5: 4248503F9F6DFEDDBFC42DE5CB990C72
%PROGRAMFILES%\PotomacSoft\TeleDesktop\ptimagdll52.dll
MD5: 2ED0250F736185CAB92C03430E0F2278 Size:143360
MD5: 2ED0250F736185CAB92C03430E0F2278
%PROGRAMFILES%\PotomacSoft\TeleDesktop\ptdsksrv.exe
MD5: 8B03819C3AB72550B0B12AF0BA0F6533 Size:32768
MD5: 8B03819C3AB72550B0B12AF0BA0F6533
%PROGRAMFILES%\PotomacSoft\TeleDesktop\ptdskmsgf.dll
MD5: B3CC7AA2F8E9CBB24EC323F64A3CB2F8 Size:12288
MD5: B3CC7AA2F8E9CBB24EC323F64A3CB2F8
%PROGRAMFILES%\PotomacSoft\TeleDesktop\ptdskdat.dll
MD5: DE15BC203D9867B916C2A04CCC775978 Size:102400
MD5: DE15BC203D9867B916C2A04CCC775978
%PROGRAMFILES%\PotomacSoft\TeleDesktop\ptdskhost.exe
MD5: 84FB458F5B21113EFCE043E0A077EC84 Size:299008
MD5: 84FB458F5B21113EFCE043E0A077EC84
%PROGRAMFILES%\PotomacSoft\TeleDesktop\ptdskclient.exe
MD5: FF6CF96647A2A6E4FC28EC94873C9778 Size:253952
MD5: FF6CF96647A2A6E4FC28EC94873C9778
- Detected Files with variable Filenames:
MD5: BD95303E283F68B39372DB9D7472F6A3 Size: 45056
%PROGRAMFILES%\PotomacSoft\TeleDesktop\teldmon1.dll
%PROGRAMFILES%\PotomacSoft\TeleDesktop\teldmon3.dll
MD5: 73FB8E23C786D499C80887EAF55D549F Size: 45056
%PROGRAMFILES%\PotomacSoft\TeleDesktop\ptshellext1.dll
%PROGRAMFILES%\PotomacSoft\TeleDesktop\ptshellext3.dll
MD5: 7DF366BF98615E740F4E34B49B1803E9 Size: 20480
%PROGRAMFILES%\PotomacSoft\TeleDesktop\pstlaunch.exe
%PROGRAMFILES%\PotomacSoft\TeleDesktop\pstlaunch.exe.ren
Detecting items list:
- Files by Name
%PROGRAMFILES%\PotomacSoft\TeleDesktop\pstlaunch.exe
%PROGRAMFILES%\PotomacSoft\TeleDesktop\ptdskclient.exe
%PROGRAMFILES%\PotomacSoft\TeleDesktop\ptdskdat.dll
%PROGRAMFILES%\PotomacSoft\TeleDesktop\ptdskhost.exe
%PROGRAMFILES%\PotomacSoft\TeleDesktop\ptdskmsgf.dll
%PROGRAMFILES%\PotomacSoft\TeleDesktop\ptdsksrv.exe
%PROGRAMFILES%\PotomacSoft\TeleDesktop\ptimagdll51.dll
%PROGRAMFILES%\PotomacSoft\TeleDesktop\ptinstass.dll
%PROGRAMFILES%\PotomacSoft\TeleDesktop\ptshellext1.dll
%PROGRAMFILES%\PotomacSoft\TeleDesktop\ptshellext3.dll
%PROGRAMFILES%\PotomacSoft\TeleDesktop\teldmon1.dll
%PROGRAMFILES%\PotomacSoft\TeleDesktop\teldmon3.dll
%START_PROGRAMSALL%\TeleDesktop\Help.lnk
%START_PROGRAMSALL%\TeleDesktop\TeleDesktop Client.lnk
%START_PROGRAMSALL%\TeleDesktop\TeleDesktop Host.lnk
%START_PROGRAMSALL%\TeleDesktop\Uninstall TeleDesktop.lnk
- Files by Directories
%PROGRAMFILES%\PotomacSoft\TeleDesktop %START_PROGRAMSALL%\TeleDesktop
- Files by CLSID or Name
CLSID=C21E0502-8958-4136-AAD0-D149444CF5E0
- Registry Keys
HKCU\Software\Local AppWizard-Generated Applications\TeleDesktop (Client)
HKCU\Software\Local AppWizard-Generated Applications\TeleDesktop (Client)\Settings
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\TeleDesktop
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ptdskhost.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ptdskhost.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SrvTest.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SrvTest.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TeleDesktop
HKLM\SOFTWARE\PotomacSoft\TeleDesktop
HKLM\SYSTEM\ControlSet001\Control\Print\Monitors\TeleDesktop Remote Printing
HKLM\SYSTEM\ControlSet001\Services\Eventlog\Application\TeleDesktop
HKLM\SYSTEM\ControlSet001\Services\PTDSKTService
HKLM\SYSTEM\ControlSet002\Control\Print\Monitors\TeleDesktop Remote Printing
HKLM\SYSTEM\ControlSet002\Services\Eventlog\Application\TeleDesktop
HKLM\SYSTEM\ControlSet002\Services\PTDSKTService
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\TeleDesktop Remote Printing
HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\TeleDesktop
HKLM\SYSTEM\CurrentControlSet\Services\PTDSKTService
- Registry Values
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=PSTeleDesktop Launcher
«
Go to Software Database