SpySheriff
Tabloul de scor amenințări
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards sunt rapoarte de evaluare pentru diferite amenințări malware care au fost colectate și analizate de echipa noastră de cercetare. EnigmaSoft Threat Scorecards evaluează și clasifică amenințările folosind mai multe valori, inclusiv factori de risc din lumea reală și potențiali, tendințe, frecvență, prevalență și persistență. EnigmaSoft Threat Scorecards sunt actualizate în mod regulat pe baza datelor și valorilor noastre de cercetare și sunt utile pentru o gamă largă de utilizatori de computere, de la utilizatorii finali care caută soluții pentru a elimina programele malware din sistemele lor până la experții în securitate care analizează amenințările.
EnigmaSoft Threat Scorecards afișează o varietate de informații utile, inclusiv:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Nivel de severitate: nivelul de severitate determinat al unui obiect, reprezentat numeric, pe baza procesului și cercetării noastre de modelare a riscului, așa cum este explicat în Criteriile noastre de evaluare a amenințărilor .
Calculatoare infectate: numărul de cazuri confirmate și suspectate ale unei anumite amenințări detectate pe computerele infectate, așa cum este raportat de SpyHunter.
Consultați și Criteriile de evaluare a amenințărilor .
| Popularity Rank: | 16,709 |
| Nivel de amenintare: | 70 % (Înalt) |
| Calculatoare infectate: | 97 |
| Prima vedere: | July 24, 2009 |
| Vazut ultima data: | August 24, 2025 |
| OS afectat(e): | Windows |
SpySheriff este o aplicație frauduloasă anti-spyware care este concepută de hackeri vicleni pentru a profita de pe urma utilizatorilor de computere credibili. SpySheriff poate fi introdus în computerul dumneavoastră de către un troian prin fisuri de securitate ale browserului sau poate fi descărcat direct de pe www.spysheriff.com. SpySheriff are capacitatea de a genera mesaje de avertizare false care apar în bara de activități. Aceste mesaje false sunt produse după o „scanare” pe care SpySheriff o emulează pentru a-i crește credibilitatea. După ce SpySheriff „detectă” paraziți pe computer, acesta vă va oferi în mod continuu să achiziționați versiunea completă a programului, pentru a elimina amenințările inexistente. Îndepărtarea imediată a SpySheriff este recomandată cu tărie.
Cuprins
Aliasuri
15 de furnizori de securitate au semnalat acest fișier ca fiind rău intenționat.
| Antivirus Vendor | Detectare |
|---|---|
| TrendMicro | PAK_Generic.001 |
| Symantec | Downloader |
| Sunbelt | Trojan-Downloader.Gen |
| Sophos | Troj/Dropper-MG |
| Panda | Adware/MediaTickets |
| NOD32 | Win32/Adware.MediaTickets.A |
| Microsoft | Adware:Win32/PurityScan.dr |
| McAfee-GW-Edition | Trojan.Crypt.XPACK.Gen |
| McAfee | potentially unwanted program Adware-PurityScan |
| K7AntiVirus | not-a-virus:AdWare.Win32.PurityScan |
| Ikarus | not-a-virus:AdWare.Win32.PurityScan.u |
| Fortinet | Adware/Purityscan |
| F-Secure | W32/Malware |
| eTrust-Vet | Win32/Secdrop.NA |
| eSafe | Win32.Downloader |
SpyHunter detectează și elimină SpySheriff
Detaliile sistemului de fișiere
| # | Nume de fișier | MD5 |
Detectări
Detectări: numărul de cazuri confirmate și suspectate ale unei anumite amenințări detectate pe computerele infectate, așa cum este raportat de SpyHunter.
|
|---|---|---|---|
| 1. | heur002.dll | ee21fd7fa9a45453ed55ccb7ce7b9aaa | 12 |
| 2. | heur000.dll | ca4822789da674e2ae4658ee4250adb5 | 12 |
| 3. | heur003.dll | bb06f2c0d34812d455aecc790aab74d4 | 12 |
| 4. | heur001.dll | 840c8e9d2aaccc87d6dad1d409e45a10 | 10 |
| 5. | hcafnqkc.exe | 564aabe45a3f7e71483a1ad2b1d31722 | 1 |
| 6. | anr10049.exe, Tempwn10049.exe, us10049[1].exe | 4c636e4d39efb85c84831973f8134bc9 | 0 |
| 7. | anr10077.exe, Tempwn10077.exe | 5353b1a6165776cd500f1ceb8080e4fe | 0 |
| 8. | anr0129.exe, winstall.exe, wn0129.exe, us0129[1].exe | eb790be93afb8481cfc43515b00976ab | 0 |
| 9. | wancp.dll | aa86aa134fbfdc57ceda90d506315ea8 | 0 |
| 10. | Installer.exe | 242a20bae9cf9cb816a447150378c02d | 0 |
| 11. | SpySheriff.exe | 0a75149998278734106f2a6f59ba965a | 0 |
| 12. | winstall.exe, webinstall[1].exe | e3e03c8bdfd1f9c7dc9f2103689c5018 | 0 |
| 13. | winstall.exe | b917ffe96edb3ae8cac14d4a19787706 | 0 |
| 14. | z16.exe | 2c66bd64d7780183a36da8e3e8394712 | 0 |
Detalii de registru
Directoare
SpySheriff poate crea următorul director sau directoare:
| %ProgramFiles%\SpySheriff |
Raport de analiză
Informatii generale
| Family Name: | SpySheriff |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
dd3b589ce72f193e5a986acf80ccee34
SHA1:
df6d8103ed4f4fac46f05654cc0ef34259c25298
SHA256:
5C683512DA68087720CFF4B6CBAE6E0B1F84E0E689E0E3265A9EB5979077646B
Mărime fișier:
459.78 KB, 459776 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have security information
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.File Traits
- .adata
- 00 section
- 2+ executable sections
- HighEntropy
- No Version Info
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 14 |
|---|---|
| Potentially Malicious Blocks: | 0 |
| Whitelisted Blocks: | 8 |
| Unknown Blocks: | 6 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\harddisk0\dr0 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\pesttrap.lnk | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\pesttrap\pesttrap.lnk | Synchronize,Write Data |
| c:\users\user\desktop\pesttrap.lnk | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Date | API Name |
|---|---|---|
| HKLM\software\classes\.key:: | RegNtPreCreateKey | |
| HKLM\software\classes\.key:: | regfile | RegNtPreCreateKey |
| HKCU\software\pesttrap::scanonstartup | RegNtPreCreateKey | |
| HKCU\software\pesttrap::playsounds | RegNtPreCreateKey | |
| HKCU\software\pesttrap::scheduledscan | RegNtPreCreateKey | |
| HKCU\software\pesttrap::scheduledscanhour | RegNtPreCreateKey | |
| HKCU\software\pesttrap::scheduledscanmin | RegNtPreCreateKey | |
| HKCU\software\pesttrap::securitylevel | RegNtPreCreateKey | |
| HKCU\software\pesttrap::uninstall | c:\users\user\downloads | RegNtPreCreateKey |
| HKCU\software\pesttrap\ie security::blockiframetags | RegNtPreCreateKey |
Show More
| HKCU\software\pesttrap\ie security::blockjavascripts | RegNtPreCreateKey | |
| HKCU\software\pesttrap\ie security::blocklocations | RegNtPreCreateKey | |
| HKCU\software\pesttrap\ie security::blockpopupwindows | RegNtPreCreateKey | |
| HKCU\software\pesttrap\ie security::blocktags | RegNtPreCreateKey | |
| HKCU\software\pesttrap\ie security::protecthomepage | RegNtPreCreateKey | |
| HKCU\software\pesttrap\process security\policies::active policy | RegNtPreCreateKey | |
| HKCU\software\pesttrap\process security\policies::process security | RegNtPreCreateKey | |
| HKCU\software\pesttrap\scan::deletefoundthreats | RegNtPreCreateKey | |
| HKCU\software\pesttrap\system security::protectactivedesktop | RegNtPreCreateKey | |
| HKCU\software\pesttrap\system security::protectautorun | RegNtPreCreateKey | |
| HKCU\software\pesttrap\system security::protecthosts | RegNtPreCreateKey | |
| HKCU\software\pesttrap\process security\policies\allowed::c:\users\user\downloads\pesttrap.exe | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\run::pesttrap | c:\users\user\downloads\PestTrap.exe | RegNtPreCreateKey |
| HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pesttrap::displayicon | c:\users\user\downloads\PestTrap.exe | RegNtPreCreateKey |
| HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pesttrap::displayname | PestTrap | RegNtPreCreateKey |
| HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pesttrap::urlinfoabout | http://www.pesttrap.com/ | RegNtPreCreateKey |
| HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pesttrap::helplink | http://www.pesttrap.com/ | RegNtPreCreateKey |
| HKLM\software\wow6432node\microsoft\windows\currentversion\uninstall\pesttrap::uninstallstring | c:\users\user\downloads\Uninstall.exe | RegNtPreCreateKey |
| HKCU\software\pesttrap::security | 낙௬ǜ | RegNtPreCreateKey |
| HKCU\software\pesttrap::securitylevel | RegNtPreCreateKey |