WebNexus
|
Description:
|
Spyware
|
|
Risk Level:
|
High
|
|
Date of First Occurence:
|
Wednesday, May 14, 2008
|
|
Software Developer:
|
(unknown)
|
|
Brief Info:
|
Adware that delivers advertising content in the form of popups to the users desktop.
|
|
Removal:
|
This threat can be removed using "Spyware
Terminator"
|
RIMUOVI SPYWARE »
Geographical Distribution of Threat "WebNexus"
Threat Info
View All
Detected Items
- Detected Files:
%WINDIR%\mynexus.exe
MD5: 41598570FDE7FD61D75012A131A00D95 Size:519877
MD5: 85E88E25D1182BD2CACEFCE392864372 Size:243377
MD5: 110F39B4422981BDA62B6A460350F5C7 Size:243531
%STARTUPALL%\xggz.exe
MD5: 7A10365C5A51F63DB6F07172C4AC0BF1 Size:199168
%WINDIR%\ryypt.dll
MD5: F6E79896008FF050BDC2DEA1FAA13E28 Size:38
%SYSDIR%\frrml.dll
MD5: 08D83B32FBED84A20AFDA14135BE3ACD Size:12288
- Detected Files with variable Filenames:
MD5: C39CF3F7A081542C3A541642CA37EFC2 Size: 227840
%SYSDIR%\POPYRY.EXE
D:\DISTRIBUTIVI\ANTIVIRUSY\viruses-20070914\vx.netlux.org\Trojan-Downloader.Win32.Qoologic.at
Detecting items list:
- Files by Name
%windir%\mynexus.exe
%sysdir%\wrakky*.exe
%windir%\wrakky*.exe
%windir%\wrraky*.exe
%sysdir%\wrraky*.exe
%WINDIR%\ryypt.dll
%sysDIR%\ryypt.dll
%sysDIR%\epppaqq.dll
%SYSDIR%\fddvckk.exe
%sysDIR%\frrml.dll
%STARTUPALL%\xggz.exe
- Files by MD5
MD5: C39CF3F7A081542C3A541642CA37EFC2 Size: 227840
- Files by CLSID or Name
CLSID=40b34d74-76d8-4385-b878-2f8db5f2795e
«
Go to Software Database