间谍警长
威胁评分卡
EnigmaSoft 威胁记分卡
EnigmaSoft 威胁记分卡是针对不同恶意软件威胁的评估报告,由我们的研究团队收集和分析。 EnigmaSoft 威胁记分卡使用多个指标对威胁进行评估和排名,包括现实世界和潜在风险因素、趋势、频率、普遍性和持续性。 EnigmaSoft 威胁记分卡会根据我们的研究数据和指标定期更新,对广泛的计算机用户有用,从寻求解决方案以从系统中删除恶意软件的最终用户到分析威胁的安全专家。
EnigmaSoft 威胁记分卡显示各种有用的信息,包括:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
严重性级别:根据我们的风险建模过程和研究,确定的对象的严重性级别,以数字形式表示,如我们的威胁评估标准中所述。
受感染计算机: SpyHunter 报告的在受感染计算机上检测到的特定威胁的确认和疑似案例数量。
另请参阅威胁评估标准。
| Popularity Rank: | 16,709 |
| 威胁级别: | 70 % (高的) |
| 受感染的计算机: | 97 |
| 初见: | July 24, 2009 |
| 最后一次露面: | August 24, 2025 |
| 受影响的操作系统: | Windows |
SpySheriff 是一种欺诈性反间谍软件应用程序,由狡猾的黑客设计,旨在从可信的计算机用户那里获利。 SpySheriff 可能被木马通过浏览器安全漏洞带入您的计算机,也可能直接从 www.spysheriff.com 下载。 SpySheriff 能够生成出现在任务栏中的错误警告消息。这些虚假消息是在 SpySheriff 模拟以提高其可信度的“扫描”之后产生的。 SpySheriff 在您的计算机上“检测到”寄生虫后,它会不断地为您提供购买程序的完整版本,以处理不存在的威胁。强烈建议立即删除 SpySheriff。
目录
别名
15 个安全供应商将此文件标记为恶意文件。
| Antivirus Vendor | 检测 |
|---|---|
| TrendMicro | PAK_Generic.001 |
| Symantec | Downloader |
| Sunbelt | Trojan-Downloader.Gen |
| Sophos | Troj/Dropper-MG |
| Panda | Adware/MediaTickets |
| NOD32 | Win32/Adware.MediaTickets.A |
| Microsoft | Adware:Win32/PurityScan.dr |
| McAfee-GW-Edition | Trojan.Crypt.XPACK.Gen |
| McAfee | potentially unwanted program Adware-PurityScan |
| K7AntiVirus | not-a-virus:AdWare.Win32.PurityScan |
| Ikarus | not-a-virus:AdWare.Win32.PurityScan.u |
| Fortinet | Adware/Purityscan |
| F-Secure | W32/Malware |
| eTrust-Vet | Win32/Secdrop.NA |
| eSafe | Win32.Downloader |
SpyHunter 检测并删除 间谍警长
文件系统详情
| # | 文件名 | MD5 |
检测
检测数: SpyHunter 报告的在受感染计算机上检测到的特定威胁的确认和疑似案例数量。
|
|---|---|---|---|
| 1. | heur002.dll | ee21fd7fa9a45453ed55ccb7ce7b9aaa | 12 |
| 2. | heur000.dll | ca4822789da674e2ae4658ee4250adb5 | 12 |
| 3. | heur003.dll | bb06f2c0d34812d455aecc790aab74d4 | 12 |
| 4. | heur001.dll | 840c8e9d2aaccc87d6dad1d409e45a10 | 10 |
| 5. | hcafnqkc.exe | 564aabe45a3f7e71483a1ad2b1d31722 | 1 |
| 6. | anr10049.exe, Tempwn10049.exe, us10049[1].exe | 4c636e4d39efb85c84831973f8134bc9 | 0 |
| 7. | anr10077.exe, Tempwn10077.exe | 5353b1a6165776cd500f1ceb8080e4fe | 0 |
| 8. | anr0129.exe, winstall.exe, wn0129.exe, us0129[1].exe | eb790be93afb8481cfc43515b00976ab | 0 |
| 9. | wancp.dll | aa86aa134fbfdc57ceda90d506315ea8 | 0 |
| 10. | Installer.exe | 242a20bae9cf9cb816a447150378c02d | 0 |
| 11. | SpySheriff.exe | 0a75149998278734106f2a6f59ba965a | 0 |
| 12. | winstall.exe, webinstall[1].exe | e3e03c8bdfd1f9c7dc9f2103689c5018 | 0 |
| 13. | winstall.exe | b917ffe96edb3ae8cac14d4a19787706 | 0 |
| 14. | z16.exe | 2c66bd64d7780183a36da8e3e8394712 | 0 |
注册表详情
目录
间谍警长 可能会创建以下目录或目录:
| %ProgramFiles%\SpySheriff |
分析报告
一般信息
| Family Name: | SpySheriff |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
dd3b589ce72f193e5a986acf80ccee34
SHA1:
df6d8103ed4f4fac46f05654cc0ef34259c25298
SHA256:
5C683512DA68087720CFF4B6CBAE6E0B1F84E0E689E0E3265A9EB5979077646B
文件大小:
459.78 KB, 459776 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have security information
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.File Traits
- .adata
- 00 section
- 2+ executable sections
- HighEntropy
- No Version Info
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 14 |
|---|---|
| Potentially Malicious Blocks: | 0 |
| Whitelisted Blocks: | 8 |
| Unknown Blocks: | 6 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\harddisk0\dr0 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\pesttrap.lnk | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\pesttrap\pesttrap.lnk | Synchronize,Write Data |
| c:\users\user\desktop\pesttrap.lnk | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | 数据 | API Name |
|---|---|---|
| HKLM\software\classes\.key:: | RegNtPreCreateKey | |
| HKLM\software\classes\.key:: | regfile | RegNtPreCreateKey |
| HKCU\software\pesttrap::scanonstartup | RegNtPreCreateKey | |
| HKCU\software\pesttrap::playsounds | RegNtPreCreateKey | |
| HKCU\software\pesttrap::scheduledscan | RegNtPreCreateKey | |
| HKCU\software\pesttrap::scheduledscanhour | RegNtPreCreateKey | |
| HKCU\software\pesttrap::scheduledscanmin | RegNtPreCreateKey | |
| HKCU\software\pesttrap::securitylevel | RegNtPreCreateKey | |
| HKCU\software\pesttrap::uninstall | c:\users\user\downloads | RegNtPreCreateKey |
| HKCU\software\pesttrap\ie security::blockiframetags | RegNtPreCreateKey |
Show More
| HKCU\software\pesttrap\ie security::blockjavascripts | RegNtPreCreateKey | |
| HKCU\software\pesttrap\ie security::blocklocations | RegNtPreCreateKey | |
| HKCU\software\pesttrap\ie security::blockpopupwindows | RegNtPreCreateKey | |
| HKCU\software\pesttrap\ie security::blocktags | RegNtPreCreateKey | |
| HKCU\software\pesttrap\ie security::protecthomepage | RegNtPreCreateKey | |
| HKCU\software\pesttrap\process security\policies::active policy | RegNtPreCreateKey | |
| HKCU\software\pesttrap\process security\policies::process security | RegNtPreCreateKey | |
| HKCU\software\pesttrap\scan::deletefoundthreats | RegNtPreCreateKey | |
| HKCU\software\pesttrap\system security::protectactivedesktop | RegNtPreCreateKey | |
| HKCU\software\pesttrap\system security::protectautorun | RegNtPreCreateKey | |
| HKCU\software\pesttrap\system security::protecthosts | RegNtPreCreateKey | |
| HKCU\software\pesttrap\process security\policies\allowed::c:\users\user\downloads\pesttrap.exe | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\run::pesttrap | c:\users\user\downloads\PestTrap.exe | RegNtPreCreateKey |
| HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pesttrap::displayicon | c:\users\user\downloads\PestTrap.exe | RegNtPreCreateKey |
| HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pesttrap::displayname | PestTrap | RegNtPreCreateKey |
| HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pesttrap::urlinfoabout | http://www.pesttrap.com/ | RegNtPreCreateKey |
| HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pesttrap::helplink | http://www.pesttrap.com/ | RegNtPreCreateKey |
| HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pesttrap::uninstallstring | c:\users\user\downloads\Uninstall.exe | RegNtPreCreateKey |
| HKCU\software\pesttrap::security | 낙௬ǜ | RegNtPreCreateKey |
| HKCU\software\pesttrap::securitylevel | RegNtPreCreateKey |