FraudTool.WinAntiVirus.ag
|
Description:
|
Rogue Security Program
|
|
Risk Level:
|
High
|
|
Date of First Occurence:
|
Thursday, July 31, 2008
|
|
Software Developer:
|
(unknown)
|
|
Brief Info:
|
Rogue/Suspect Anti-Spyware Product
"Rogue/Suspect" means that these products are of unknown, questionable, or dubious value as anti-spyware protection.
|
|
Removal:
|
This threat can be removed using "Spyware
Terminator"
|
SCAN & REMOVE NOW »
Geographical Distribution of Threat "FraudTool.WinAntiVirus.ag"
Threat Info
View All
Detected Items
- Detected Files:
%PROGRAMFILES%\PCHealthCenter\0.exe
MD5: BD4E88FC20D2AC29B7B523F426B1BD3B Size:28160
- Detected Files with variable Filenames:
MD5: F27ED912FEB83B13DB72F4D61497AD00 Size: 28160
d:\System Volume Information\_restore{F5665B7E-B0E0-408F-A57D-9CD2550F5F81}\RP24\A0014540.exe
d:\System Volume Information\_restore{F5665B7E-B0E0-408F-A57D-9CD2550F5F81}\RP22\A0005531.exe
MD5: 7B1ACD3CDB0AA7A08F3F5BF909DEFF42 Size: 1100340
%USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\TALWPPID\4683lt[1].exe
%TEMP%\lwpwer.exe
%USERPROFILE%\Local Settings\Temp\lwpwer.exe
%USERPROFILE%\Local Settings\Temporary Internet Files\Content.IE5\XW6I7YP3\4683lt[1].exe
%SystemDiskRoot%\Users\Quentin.Francine-PC\AppData\Local\Temp\lwpwer.exe
%SystemDiskRoot%\Users\Quentin.Francine-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N20SAFSB\4683lt[1].exe
%USERPROFILE%\Configuracin local\Temp\lwpwer.exe
%USERPROFILE%\Lokale Einstellungen\Temp\lwpwer.exe
Configuraes locais\Temporary Internet Files\Content.IE5\5A2IDY1M\4683lt[1].exe
Detecting items list:
- Files by MD5
MD5: 7B1ACD3CDB0AA7A08F3F5BF909DEFF42 Size: 1100340
MD5: BD4E88FC20D2AC29B7B523F426B1BD3B Size: 28160
MD5: F27ED912FEB83B13DB72F4D61497AD00 Size: 28160
«
Go to Software Database