|
|
Trojan.winfirewall Trojan Information
| Name: |
Trojan.winfirewall |
| Category: |
Trojan |
| Alias: |
- Alias: BackDoor-TD, Backdoor.Contempt, Backdoor.Contempt |
| Advice: |
Remove |
| Risk: |
Severe Risk
Severe threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction and exploits are in the wild. There exists a high possibility of potential system damage or security flaw. Attacker has complete control over your computer or install new software on your machine. |
| Description:
|
; This file is generated by AppHunter
; Please contact support@cyberdefender.com for more details
[Summary]
Discovered=04/24/2005 09:04:00
ID=22DFBB850A12CFB6BC59CD55D4F62EC8
ID2=206196,78D8F252851DCD2783964ACCFE62E2FE
ID3=204800,1120511AC96908FAD3A36DC282CF5CB4
MD5=442EF2E1FC2DC23C24F420BE975475C6
Size=206196
Filename=winfirewall.exe
Company=N/A
Risk=5.6
Virus=BackDoor-CGX ***
[Risk Analyzer]
HookPlugin=6
AutoRun=4
NonBrand=10
FileCreated=4
FileCreatedInWinSys=4
CloneThreat=4
RunProcess=4
ServiceCreated=10
McAfee=8
[Virus Known As (McAfee)]
BackDoor-CGX=1
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServiceswinfire]
ImagePath=C:WINDOWSsystem32winfirewall.exe
[Hook]
c:windowssystem32keyspy.dll=1
[ProcessInjected]
1540=c:windowsexplorer.exe
1704=c:program filesuwcdsuwcdsvr.exe
1728=c:program filesmessengermsmsgs.exe
1756=c:program fileseblocsspyblocsglfb.exe
1776=c:program filesshadowstorshadowusershadowuser.exe
1908=c:apphunteruwapphunter.exe
2128=c:windowssystem32winfirewall.exe
[FileCreated]
c:windowssystem32winfirewall.exe=1
c:windowssystem32keyspy.dll=1
[ProcessCreated]
C:WINDOWSsystem32cmd.exe=1
[ThreadCreated]
Count=2
|
| Signatures:
|
process: winfirewall.exe: MD5 Hash: 50904335fa22571c8a9.. |
| Type: |
Trojan - A Trojan software is any software on a user's computer that the user is not aware or intentionally installed. Most Trojan software is designed to perform some sort of actions that could jeopardize the user's security or privacy. |
Top Trojan Visited Pages:
Tro.Downloader.loadadv - 411 visits
Enable Regedit - 195 visits
Java.ClassLoader.Dummy.d - 187 visits
Trojan.BankerSpy - 179 visits
RBot.steam - 86 visits
Startup.NameShifter.Xgtray - 77 visits
Tro.Bagle.SP - 59 visits
LRPatch Trojan - 58 visits
Trojan.BHO.NameShifter.EZ - 55 visits
Tro.YourStartingPage - 54 visits
Random Trojan Pages:
Trojan.BHO.NameShifter.HB
Tro.AntiSpywareScam.B
Exec Demo 2 Trojan
Startup.NameShifter.LR
SennaSpy Trojan Generator 3.01
Trojan.P2PNetwork
Trojan.BHO.NameShifter.HR
Icup Trojan - Alias: Trojan.PSW.Icup
Tro.Downloader.Musah
Contempt - Alias: BackDoor-TD, Backdoor.Contempt, Backdoor.Contempt
|
|