SlideShare uma empresa Scribd logo
1 de 12
Paltalk Rogue Trojan loader from PalNet Ad Server Captured by Sunny Sky50m @PCTECH
Reason for This report Popup below produced by Paltalk Today Ad. 27 March-2010 ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
The Rogue Online Scanner  The Paltalk Today window popped up from the background to the top of the desktop. It behaved like any webpage but without an address bar.  In this window, it shows a fake Windows System Task on the left with fake Explorer folders and fake trojan scanner results.  It looked like an active animated online program, but was actually a harmless animated GIF or PNG file, thus going undetected by any AntiMalware software.  In this case just pretending to be an online Security Scan but with an embedded hyperlink supplied by PALNET server and if clicked went straight to the resulting Trojan server to initiate a download.. “ to Fix your Infected Computer!  (not!) <<< Clicking anywhere on the Paltalk Today window triggers the Trojan download . ”inst.exe”
Where does the Trojan come from? whois 85.12.44.148?  inetnum:        85.12.44.128 - 85.12.44.255 netname:        XS-24 descr:          XS-24 international ltd country:        nl admin-c:        PL2400-RIPE tech-c:         TW1148-RIPE status:         ASSIGNED PA mnt-by:         EUROACCESS-MNT source:         RIPE # Filtered person:         PC Leurink address:        EuroAccess Enterprises Ltd. address:        Alsacelaan 5 address:        5627 CA Eindhoven, The Netherlands phone:          +31 (0)20-7173209              +31 (0)20-7173209       fax-no:         +31 (0)40-2488764 e-mail:                                                                                                mnt-by:         EUROACCESS-MNT nic-hdl:        PL2400-RIPE source:         RIPE # Filtered person:         TA Westervoorde address:        EuroAccess Enterprises Ltd. address:        Alsacelaan 5 address:        5627 CA Eindhoven, The Netherlands phone:          +31 (0)20-7173209              +31 (0)20-7173209       fax-no:         +31 (0)40-2488764 e-mail:                                                                                                mnt-by:         EUROACCESS-MNT nic-hdl:        TW1148-RIPE source:         RIPE # Filtered
How is Paltalk infecting users? ,[object Object],[object Object],[object Object]
Which AV missed detecting this Malware? inst.exe  was saved, and was sent to  www.virustotalcom  for analysis. The results showed this file could kill processes, read & write files using in the kernel32.dll ( 2 imports ) > USER32.dll: CreateWindowExA, GetTaskmanWindow, MessageBoxA, GetMessageExtraInfo, UpdateWindow, CreateWindowExW, SendMessageA > KERNEL32.dll: ExitProcess, CreateFileW, WriteFile, ReadFile, GetVersionExW, GetModuleHandleW, DuplicateHandle, CloseHandle VIRUS-TOTAL RESULTS File  inst.exe  received on 2010.03.27 21:49:18 (UTC) Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED Result: 8/42 (19.05%)  {detected by 8 of 42 malware software types} Version  Last Update  Result a-squared 4.5.0.50 2010.03.27 - AhnLab-V3 5.0.0.2 2010.03.27 - AntiVir 7.10.5.241 2010.03.26 - Antiy-AVL 2.0.3.7 2010.03.26 - Authentium 5.2.0.5 2010.03.27 - Avast 4.8.1351.0 2010.03.27 - Avast5 5.0.332.0 2010.03.27 - AVG 9.0.0.787 2010.03.27 - BitDefender 7.2 2010.03.27 - CAT-QuickHeal 10.00 2010.03.27 - ClamAV 0.96.0.0-git 2010.03.27 - Comodo 4407 2010.03.27 - DrWeb 5.0.1.12222 2010.03.27 - eSafe 7.0.17.0 2010.03.25 - eTrust-Vet 35.2.7391 2010.03.26 - F-Prot 4.5.1.85 2010.03.27 - F-Secure 9.0.15370.0 2010.03.27 - Fortinet 4.0.14.0 2010.03.27 - GData 19 2010.03.27 - Ikarus T3.1.1.80.0 2010.03.27 - Jiangmin 13.0.900 2010.03.27 - K7AntiVirus 7.10.1004 2010.03.22 - Kaspersky 7.0.0.125 2010.03.27 Packed.Win32.Krap.ai McAfee 5933 2010.03.27 FakeAlert-KW.e McAfee+Artemis 5933 2010.03.27 FakeAlert-KW.e McAfee-GW-Edition 6.8.5 2010.03.27 Heuristic.BehavesLike.Win32.Packed.K Microsoft 1.5605 2010.03.27 Trojan:Win32/Winwebsec NOD32 4978 2010.03.26 - Norman 6.04.10 2010.03.27 - nProtect 2009.1.8.0 2010.03.27 - Panda 10.0.2.2 2010.03.27 - PCTools 7.0.3.5 2010.03.27 - Prevx 3.0 2010.03.27 - Rising 22.40.05.04 2010.03.27 - Sophos 4.52.0 2010.03.27 - Sunbelt 6101 2010.03.26 FraudTool.Win32.SecurityTool (v) Symantec 20091.2.0.41 2010.03.27 Suspicious.Insight TheHacker 6.5.2.0.246 2010.03.27 Trojan/FakeAV.gen TrendMicro 9.120.0.1004 2010.03.27 - VBA32 3.12.12.2 2010.03.27 - ViRobot 2010.3.27.2248 2010.03.27 - VirusBuster 5.0.27.0 2010.03.27 -
Here is a summary of Paltalk’s Infection trigger mechanism ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Paltalk.exe file creation log with trojan ,[object Object],[object Object]
No signs of Paltalk or PC being Infected Event ,[object Object],[object Object],[object Object]
What does VirusTotal call this trojan? ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
What do we expect from Paltalk? ,[object Object],[object Object],[object Object]
What else could be done? ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]

Mais conteúdo relacionado

Destaque

Tecnologiaeducativa ines dousdebes
Tecnologiaeducativa ines dousdebesTecnologiaeducativa ines dousdebes
Tecnologiaeducativa ines dousdebesInes Dousdebes
 
Barbie powerpoint con musica
Barbie powerpoint con musicaBarbie powerpoint con musica
Barbie powerpoint con musicaMariCarmenML
 
PressDoc - A quick walkthrough
PressDoc - A quick walkthroughPressDoc - A quick walkthrough
PressDoc - A quick walkthroughStefan Borsje
 
Horoscopo Celta Aliso
Horoscopo Celta AlisoHoroscopo Celta Aliso
Horoscopo Celta Alisoguestaccddad
 
BITzen, cloud computing y como crear una startup en Canarias
BITzen, cloud computing y como crear una startup en CanariasBITzen, cloud computing y como crear una startup en Canarias
BITzen, cloud computing y como crear una startup en CanariasKilian Barrera
 
T 7 sector primari
T 7 sector primariT 7 sector primari
T 7 sector primarigraciajt
 
Marketing Tactics of Top Performers
Marketing Tactics of Top PerformersMarketing Tactics of Top Performers
Marketing Tactics of Top PerformersAct-On Software
 
Entrepreneur à l'essai avec la Couveuse Normandie
Entrepreneur à l'essai avec la Couveuse NormandieEntrepreneur à l'essai avec la Couveuse Normandie
Entrepreneur à l'essai avec la Couveuse NormandieBGE Normandie
 
Caso problema de fisiopatología
Caso problema de fisiopatologíaCaso problema de fisiopatología
Caso problema de fisiopatologíaEdim Parisaca
 
Adaptive Go-To-Market Plan for a Business DNA Search Engine: VisionaryD Software
Adaptive Go-To-Market Plan for a Business DNA Search Engine: VisionaryD SoftwareAdaptive Go-To-Market Plan for a Business DNA Search Engine: VisionaryD Software
Adaptive Go-To-Market Plan for a Business DNA Search Engine: VisionaryD SoftwareRod King, Ph.D.
 

Destaque (17)

La vida
La vidaLa vida
La vida
 
Tecnologiaeducativa ines dousdebes
Tecnologiaeducativa ines dousdebesTecnologiaeducativa ines dousdebes
Tecnologiaeducativa ines dousdebes
 
Barbie powerpoint con musica
Barbie powerpoint con musicaBarbie powerpoint con musica
Barbie powerpoint con musica
 
CRONOLOGÍA DEL INTERNET EN BOLVIA
CRONOLOGÍA DEL INTERNET EN BOLVIACRONOLOGÍA DEL INTERNET EN BOLVIA
CRONOLOGÍA DEL INTERNET EN BOLVIA
 
PressDoc - A quick walkthrough
PressDoc - A quick walkthroughPressDoc - A quick walkthrough
PressDoc - A quick walkthrough
 
Horoscopo Celta Aliso
Horoscopo Celta AlisoHoroscopo Celta Aliso
Horoscopo Celta Aliso
 
BITzen, cloud computing y como crear una startup en Canarias
BITzen, cloud computing y como crear una startup en CanariasBITzen, cloud computing y como crear una startup en Canarias
BITzen, cloud computing y como crear una startup en Canarias
 
Dibujos sheila
Dibujos sheilaDibujos sheila
Dibujos sheila
 
T 7 sector primari
T 7 sector primariT 7 sector primari
T 7 sector primari
 
Métodos cuantitativos en evaluación
Métodos cuantitativos en evaluaciónMétodos cuantitativos en evaluación
Métodos cuantitativos en evaluación
 
Buchstart - Né pour lire
Buchstart - Né pour lireBuchstart - Né pour lire
Buchstart - Né pour lire
 
Marketing Tactics of Top Performers
Marketing Tactics of Top PerformersMarketing Tactics of Top Performers
Marketing Tactics of Top Performers
 
Entrepreneur à l'essai avec la Couveuse Normandie
Entrepreneur à l'essai avec la Couveuse NormandieEntrepreneur à l'essai avec la Couveuse Normandie
Entrepreneur à l'essai avec la Couveuse Normandie
 
Caso problema de fisiopatología
Caso problema de fisiopatologíaCaso problema de fisiopatología
Caso problema de fisiopatología
 
Iberia´s HCC Project
Iberia´s HCC ProjectIberia´s HCC Project
Iberia´s HCC Project
 
El berbo
El berboEl berbo
El berbo
 
Adaptive Go-To-Market Plan for a Business DNA Search Engine: VisionaryD Software
Adaptive Go-To-Market Plan for a Business DNA Search Engine: VisionaryD SoftwareAdaptive Go-To-Market Plan for a Business DNA Search Engine: VisionaryD Software
Adaptive Go-To-Market Plan for a Business DNA Search Engine: VisionaryD Software
 

Último

Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdfSandro Moreira
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...apidays
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesrafiqahmad00786416
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Orbitshub
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...apidays
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistandanishmna97
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native ApplicationsWSO2
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024The Digital Insurer
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Victor Rentea
 
Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfOverkill Security
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 

Último (20)

Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdf
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 

Paltalk Rogue Trojan Loader From Palnet Ad Server

  • 1. Paltalk Rogue Trojan loader from PalNet Ad Server Captured by Sunny Sky50m @PCTECH
  • 2.
  • 3. The Rogue Online Scanner The Paltalk Today window popped up from the background to the top of the desktop. It behaved like any webpage but without an address bar. In this window, it shows a fake Windows System Task on the left with fake Explorer folders and fake trojan scanner results. It looked like an active animated online program, but was actually a harmless animated GIF or PNG file, thus going undetected by any AntiMalware software. In this case just pretending to be an online Security Scan but with an embedded hyperlink supplied by PALNET server and if clicked went straight to the resulting Trojan server to initiate a download.. “ to Fix your Infected Computer! (not!) <<< Clicking anywhere on the Paltalk Today window triggers the Trojan download . ”inst.exe”
  • 4. Where does the Trojan come from? whois 85.12.44.148? inetnum:        85.12.44.128 - 85.12.44.255 netname:        XS-24 descr:          XS-24 international ltd country:        nl admin-c:        PL2400-RIPE tech-c:         TW1148-RIPE status:         ASSIGNED PA mnt-by:         EUROACCESS-MNT source:         RIPE # Filtered person:         PC Leurink address:        EuroAccess Enterprises Ltd. address:        Alsacelaan 5 address:        5627 CA Eindhoven, The Netherlands phone:          +31 (0)20-7173209              +31 (0)20-7173209       fax-no:         +31 (0)40-2488764 e-mail:                                                                                             mnt-by:         EUROACCESS-MNT nic-hdl:        PL2400-RIPE source:         RIPE # Filtered person:         TA Westervoorde address:        EuroAccess Enterprises Ltd. address:        Alsacelaan 5 address:        5627 CA Eindhoven, The Netherlands phone:          +31 (0)20-7173209              +31 (0)20-7173209       fax-no:         +31 (0)40-2488764 e-mail:                                                                                             mnt-by:         EUROACCESS-MNT nic-hdl:        TW1148-RIPE source:         RIPE # Filtered
  • 5.
  • 6. Which AV missed detecting this Malware? inst.exe was saved, and was sent to www.virustotalcom for analysis. The results showed this file could kill processes, read & write files using in the kernel32.dll ( 2 imports ) > USER32.dll: CreateWindowExA, GetTaskmanWindow, MessageBoxA, GetMessageExtraInfo, UpdateWindow, CreateWindowExW, SendMessageA > KERNEL32.dll: ExitProcess, CreateFileW, WriteFile, ReadFile, GetVersionExW, GetModuleHandleW, DuplicateHandle, CloseHandle VIRUS-TOTAL RESULTS File inst.exe received on 2010.03.27 21:49:18 (UTC) Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED Result: 8/42 (19.05%) {detected by 8 of 42 malware software types} Version Last Update Result a-squared 4.5.0.50 2010.03.27 - AhnLab-V3 5.0.0.2 2010.03.27 - AntiVir 7.10.5.241 2010.03.26 - Antiy-AVL 2.0.3.7 2010.03.26 - Authentium 5.2.0.5 2010.03.27 - Avast 4.8.1351.0 2010.03.27 - Avast5 5.0.332.0 2010.03.27 - AVG 9.0.0.787 2010.03.27 - BitDefender 7.2 2010.03.27 - CAT-QuickHeal 10.00 2010.03.27 - ClamAV 0.96.0.0-git 2010.03.27 - Comodo 4407 2010.03.27 - DrWeb 5.0.1.12222 2010.03.27 - eSafe 7.0.17.0 2010.03.25 - eTrust-Vet 35.2.7391 2010.03.26 - F-Prot 4.5.1.85 2010.03.27 - F-Secure 9.0.15370.0 2010.03.27 - Fortinet 4.0.14.0 2010.03.27 - GData 19 2010.03.27 - Ikarus T3.1.1.80.0 2010.03.27 - Jiangmin 13.0.900 2010.03.27 - K7AntiVirus 7.10.1004 2010.03.22 - Kaspersky 7.0.0.125 2010.03.27 Packed.Win32.Krap.ai McAfee 5933 2010.03.27 FakeAlert-KW.e McAfee+Artemis 5933 2010.03.27 FakeAlert-KW.e McAfee-GW-Edition 6.8.5 2010.03.27 Heuristic.BehavesLike.Win32.Packed.K Microsoft 1.5605 2010.03.27 Trojan:Win32/Winwebsec NOD32 4978 2010.03.26 - Norman 6.04.10 2010.03.27 - nProtect 2009.1.8.0 2010.03.27 - Panda 10.0.2.2 2010.03.27 - PCTools 7.0.3.5 2010.03.27 - Prevx 3.0 2010.03.27 - Rising 22.40.05.04 2010.03.27 - Sophos 4.52.0 2010.03.27 - Sunbelt 6101 2010.03.26 FraudTool.Win32.SecurityTool (v) Symantec 20091.2.0.41 2010.03.27 Suspicious.Insight TheHacker 6.5.2.0.246 2010.03.27 Trojan/FakeAV.gen TrendMicro 9.120.0.1004 2010.03.27 - VBA32 3.12.12.2 2010.03.27 - ViRobot 2010.3.27.2248 2010.03.27 - VirusBuster 5.0.27.0 2010.03.27 -
  • 7.
  • 8.
  • 9.
  • 10.
  • 11.
  • 12.