Remote Control (DataSet)
|
Description:
|
Spyware
|
|
Risk Level:
|
Low
|
|
Date of First Occurence:
|
Thursday, May 22, 2008
|
|
Software Developer:
|
(unknown)
|
|
Brief Info:
|
Spyware is computer software that is installed surreptitiously on a personal computer to intercept or take partial control over the user's interaction with the computer, without the user's informed consent.
|
|
Removal:
|
This threat can be removed using "Spyware
Terminator"
|
SUPPRIMER SPYWARE »
Geographical Distribution of Threat "Remote Control (DataSet)"
Threat Info
View All
Detected Items
- Detected Files:
%PROGRAMFILES%\DataSet\Remote Control\Alt\_SETUP.DLL
MD5: 6F071963F080D93B18E0804CB53EE373 Size:11264
%PROGRAMFILES%\DataSet\Remote Control\Alt\_ISDEL.EXE
MD5: 7DA2B92892717A8C8DDF0850BDF22256 Size:8192
%PROGRAMFILES%\DataSet\Remote Control\Alt\SETUP.EXE
MD5: 210007856C25B5001FE57949DAAE07DC Size:59904
%PROGRAMFILES%\DataSet\Remote Control\bbpass.exe
MD5: 39742EA07FB90E502A044CE8B19C685F Size:176128
%PROGRAMFILES%\DataSet\Remote Control\Bblsrvdl.dll
MD5: B37850E38C28236240F8F87FAF1077F6 Size:233472
%PROGRAMFILES%\DataSet\Remote Control\bbLsrv.exe
MD5: 0268B645C2CE53187BDDC63AB2606EA3 Size:307200
%PROGRAMFILES%\DataSet\Remote Control\bbsrvb.exe
MD5: 7E8312280E725A1B9F1C54B0990841A8 Size:774144
%PROGRAMFILES%\DataSet\Remote Control\config.exe
MD5: E8BADA354AECA1859746DB5F89AF2DE3 Size:410112
%PROGRAMFILES%\DataSet\Remote Control\bbgatew.exe
MD5: B4F2D194A8892B1D6A1F828FF6D02C61 Size:249856
%PROGRAMFILES%\DataSet\Remote Control\bbLsrvsr.exe
MD5: 0E1A17D5D215EC0CEC08269A0F6EC277 Size:65536
%PROGRAMFILES%\DataSet\Remote Control\bbsrvsr.exe
MD5: E552875DAECC04AB6F450E39A2241352 Size:487424
MD5: 9BC4942F5A51ACBCB5DE6F9883338E07 Size:593920
%PROGRAMFILES%\DataSet\Remote Control Server\bbsrvb.exe
MD5: B2C2278723495CEE3894D506F8040117 Size:524288
MD5: 2493C6BC0284DC32B035B62ABFD7E8D3 Size:591872
MD5: 0AA65559B148966926CAFE06DE3E74F6 Size:708096
%PROGRAMFILES%\DataSet\Remote Control\bbcli.exe
MD5: 2AE1F7F632AE4A82578AA168B2DE9B64 Size:1339392
%PROGRAMFILES%\DataSet\Remote Control Server\bbpass.exe
MD5: 65DAB1AF37E64C29AB90B88C02E6EED6 Size:23040
- Detected Files with variable Filenames:
MD5: ECFC453D0DCFA82A1257D10FDDDC58A0 Size: 31232
%PROGRAMFILES%\DataSet\Remote Control\SOC32MSG.dll
%PROGRAMFILES%\DataSet\Remote Control Server\SOC32MSG.dll
MD5: EC29E94CA69BF829B2832D8416C64E72 Size: 44544
%PROGRAMFILES%\DataSet\Remote Control\bbhooks.dll
%PROGRAMFILES%\DataSet\Remote Control Server\bbhooks.dll
MD5: 23217929672D5AEEB9E86991C55F77B6 Size: 132096
%PROGRAMFILES%\DataSet\Remote Control\BBEW.EXE
%PROGRAMFILES%\DataSet\Remote Control Server\BBEW.EXE
MD5: E1E0FF6A598CFA2AF14A1676E413E54C Size: 183808
%PROGRAMFILES%\DataSet\Remote Control\bbenumus.dll
%PROGRAMFILES%\DataSet\Remote Control Server\bbenumus.dll
Detecting items list:
- Files by Name
%PROGRAMFILES%\DataSet\Remote Control\BBCLI.EXE
%PROGRAMFILES%\DataSet\Remote Control\SOC32MSG.dll
%PROGRAMFILES%\DataSet\Remote Control Server\bbenumus.dll
%PROGRAMFILES%\DataSet\Remote Control Server\BBEW.EXE
%PROGRAMFILES%\DataSet\Remote Control Server\bbhooks.dll
%PROGRAMFILES%\DataSet\Remote Control Server\bbpass.exe
%PROGRAMFILES%\DataSet\Remote Control Server\bbsrvb.exe
%PROGRAMFILES%\DataSet\Remote Control Server\SOC32MSG.dll
%START_PROGRAMSALL%\Remote Control\Remote Control.lnk
%START_PROGRAMSALL%\Remote Control\Speed up Remote Control.lnk
%START_PROGRAMSALL%\Remote Control Server\Remote Control Server.lnk
- Files by Directories
%PROGRAMFILES%\DataSet\Remote Control %START_PROGRAMSALL%\Remote Control Server
- Registry Keys
HKCU\Software\DataSet\Remote Control
HKCU\Software\DataSet\Remote Control Server
HKCU\Software\DataSet\Remote Control Server\Recent File List
HKCU\Software\DataSet\Remote Control Server\Settings
HKLM\SOFTWARE\DataSet\Remote Control
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Remote Control
HKLM\SOFTWARE\DataSet\Remote Control Server
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Remote Control Server
- Registry Values
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=Remote Control Server
«
Go to Software Database