ADVANCED WINDOWSCARE V2.4.0.889 PRO.EXE

What you should do about ADVANCED WINDOWSCARE V2.4.0.889 PRO.EXE:

The most common objects with the name of ADVANCED WINDOWSCARE V2.4.0.889 PRO.EXE have yet to be classified as safe by our research department.

If you are concerned that your PC might be infected why not try our Free version of Prevx 3.0. It will thoroughly check your PC for millions of active Spyware and malware infections and takes less than 2 minutes. Don't take the risk, check your PC now.

Download Prevx 3.0

What we know about ADVANCED WINDOWSCARE V2.4.0.889 PRO.EXE:

ADVANCED WINDOWSCARE V2.4.0......EXE

AUTOMATED MALWARE PROFILE, ANALYSIS, REMOVAL AND SIGNATURE INFORMATION:

DEFINITION OF: ADVANCED WINDOWSCARE V2.4.0......EXE

MALWARE ASSESSMENT: PREVX 4 AXES OF EVIL METHODOLOGY

1. COVERT ANALYSIS OF: ADVANCED WINDOWSCARE V2.4.0......EXE

  • File Names Used: 85784
  • Paths Used: 1825
  • Common File Name: ADVANCED WINDOWSCARE V2.4.0......EXE
  • Common Path: %STARTMENU%\
  • Vendor Information: Microsoft Corporation
  • Product Information: Generic Host Process for Win32 Services
  • Version Information: 5.1.2600.2180
  • ADVANCED WINDOWSCARE V2.4.0......EXE may use 85,784 or more path and file names, these are the most common:
  • 1 :%DOCUMENTS%\MORPHEUS SHARED\DOWNLOADS\(UNVERIFIED) MUVEE AUTOPRODU.....EXE
  • 2 :%DOCUMENTS%\MORPHEUS SHARED\DOWNLOADS\CLONEDVD MOBILE 1.1.3.0 RELE.....EXE
  • 3 :%documents%\my downloads\incomplete\T-233472-SONY VEGAS V7.0B.EXE
  • 4 :%DOCUMENTS%\MY MUSIC\FULL SPEED OPTIMISER.EXE
  • 5 :%DOCUMENTS%\MY MUSIC\GUITAR PRO 5.1.EXE
  • 6 :%DOCUMENTS%\MY VIDEOS\UPLINK HACKER ELITE.EXE
  • 7 :%profiles%\beton.beton-a674g869w\incomplete\T-233472-CATERPILLAR CONSTRU.....EXE
  • 8 :%PROFILES%\CHRIS\SHARED\GARMIN MAPSOURCE CITYNAVIGAT.....EXE
  • 9 :%profiles%\godfrey job\shared\CAKEWALK SONAR V5.0 PRODUCER.....EXE
  • 10:%profiles%\john n julie\incomplete\T-233472-PASSWORD MANAGER V1.0.EXE
  • 11:%profiles%\liviu\incomplete\T-233472-HARD TRUCK 18 WHEE.....EXE
  • 12:%profiles%\mlivo\incomplete\T-233472-ZONEALARM INTERNET .....EXE
  • 13:%PROFILES%\O
  • File Name Structure: Normal
  • File and Path Structure: Suspicious, unusually high number of file and path combinations

2. RELATIONSHIP ANALYSIS OF: ADVANCED WINDOWSCARE V2.4.0......EXE

  • Malicious Objects Created: 13 objects
  • Malicious Creators: 8
  • Malware Run Keys: Creates registry run keys for known malware objects
  • Self Persists:
  • Antivirus Detection: Yes, detected by one or more 3rd party Antivirus product
  • Anti-Spyware Detection: Yes, detected by one or more 3rd party Anti-Spyware product

3. ACTIVITY ANALYSIS OF: ADVANCED WINDOWSCARE V2.4.0......EXE

  • The following behaviors have been observed for this object:
  • Installs programs.
  • Deletes programs.
  • Invokes dll components.
  • Registers Browser Help Objects.
  • Creates Run Keys.
  • Modifies the hostsfile.
  • Runs temporary programs.
  • Runs other programs.
  • Communicates with web sites using httpout protocols.
  • Scans active processes.
  • Terminates processes.
  • Hijacks running processes.
  • Inspects email address books.
  • Creates registry entries.
  • Creates run keys for known malware.
  • Creates cautioned software.
  • Creates known malware.
  • Creates copies of itself.

4. PROPAGATION ANALYSIS OF: ADVANCED WINDOWSCARE V2.4.0......EXE

  • Malware Group Propagation Rate: Moderate (spreading)
  • Malware Group: Trojan SystemPoser
  • Copyright Prevx Limited 2005, 2006

Copyright Prevx Ltd
Page Generated on Nov 7, 2009 21:41