Content

Generic PUP.z!67b000c01f85

Type
Program
SubType
-
Discovery Date
08/28/2009
Length
363016
Minimum DAT
5723 (08/28/2009)
Updated DAT
5723 (08/28/2009)
Minimum Engine
5300.2777
Description Added
08/28/2009
Description Modified
08/28/2009 10:09 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This software is not a virus or a Trojan. It is detected as a "potentially unwanted program" (PUP). PUPs are any piece of software that a reasonably security- or privacy-minded computer user may want to be informed of and, in some cases, remove. PUPs are often made by a legitimate corporate entity for some beneficial purpose, but they alter the security state of the computer on which they are installed, or the privacy posture of the user of the system, such that most users will want to be aware of them.

File PropertyProperty Value
FileName25c48b3339766c08435de9d251cea0bda67e55e6.exe
McAfee ArtemisArtemis!67b000c01f85
McAfee DetectionGeneric PUP.z
Length363,016 bytes
CRCC8D201D7
MD567B000C01F85AD2077D46E38DA84DEDC
SHA125C48B3339766C08435DE9D251CEA0BDA67E55E6

Other Common Detection Aliases

Company NameDetection Name
ahnlabWin32/Champ
avastWin32:SkiMorph [Cryp]
AVG (GriSoft)SHeur2.NVW (Trojan horse)
AviraTR/Crypt.XPACK.Gen
BitDefenderTrojan.FakeAlert.AVE
Dr.WebTrojan.Packed.142
EsetWin32/Adware.SpywareProtect2009 (application)
FortiNetMisc/WinSpywareProtect
F-ProtW32/Backdoor2.DTVQ
Kasperskynot-a-virus:FraudTool.Win32.WinSpywareProtect.em
microsoftTrojan:Win32/FakeSpypro
normanW32/Smalltroj.LAYJ
pandaAdware/WinSpywareProtect (spyware)
SophosMal/UnkPack-Fam
SymantecDownloader.MisleadApp
Trend MicroTROJ_GEN.0Z0606
vba32Win32.Adware.SpywareProtect2009
V-BusterFraudtool.WinSpywareProtect.H (trojan)
Vet (Computer Associates)
Win32/FakeAv.ABD

Avert® Labs has observed the following system activities:

ActivityRisk Level
Uses shared memory of other processes
Low

Other detections that have been observed.

FileNameMcAfee Supported
%WINDIR%\sysguard.exe
Generic PUP.z

System Changes

These are general defaults for typical path variables. (Although they may differ, these examples are common.):
%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files

The following files were analyzed:

  • %USERPROFILE%\local settings\temp\25c48b3339766c08435de9d251cea0bda67e55e6.exe
  • The following files have been added to the system:

  • %WINDIR%\sysguard.exe
  • The following registry elements have been changed:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\currentversion\run\
    • sysguard = c:\windows\sysguard.exe
  • Symptoms

    This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.

    Method of Infection

    This is not a virus or Trojan. PUPs do not "infect" systems. They may be installed by a user individually or possibly as a part of a software package (in a bundle, for example).

    Removal

    AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.

    Additional Windows ME/XP removal considerations

    Variants

    Variants

      N/A

    All Information

    Overview -

    McAfee® Avert® Labs recognizes that this program may have legitimate uses in contexts where an authorized administrator has knowingly installed this application. If you agreed to a license agreement for this or another bundled application, you may have legal obligations with regard to removing this software, or to using the host application without this software. Please contact the software vendor for further information.

    See http://vil.nai.com/vil/DATReadme.aspx for a list of program detections added to the DATs.

    See http://vil.nai.com/vil/pups/configuration.aspx for information about how to enable, disable, and exclude the detection of legitimately installed programs.

    This software is not a virus or a Trojan. It is detected as a "potentially unwanted program" (PUP). PUPs are any piece of software that a reasonably security- or privacy-minded computer user may want to be informed of and, in some cases, remove. PUPs are often made by a legitimate corporate entity for some beneficial purpose, but they alter the security state of the computer on which they are installed, or the privacy posture of the user of the system, such that most users will want to be aware of them.

    Characteristics

    Characteristics -

    This software is not a virus or a Trojan. It is detected as a "potentially unwanted program" (PUP). PUPs are any piece of software that a reasonably security- or privacy-minded computer user may want to be informed of and, in some cases, remove. PUPs are often made by a legitimate corporate entity for some beneficial purpose, but they alter the security state of the computer on which they are installed, or the privacy posture of the user of the system, such that most users will want to be aware of them.

    File PropertyProperty Value
    FileName25c48b3339766c08435de9d251cea0bda67e55e6.exe
    McAfee ArtemisArtemis!67b000c01f85
    McAfee DetectionGeneric PUP.z
    Length363,016 bytes
    CRCC8D201D7
    MD567B000C01F85AD2077D46E38DA84DEDC
    SHA125C48B3339766C08435DE9D251CEA0BDA67E55E6

    Other Common Detection Aliases

    Company NameDetection Name
    ahnlabWin32/Champ
    avastWin32:SkiMorph [Cryp]
    AVG (GriSoft)SHeur2.NVW (Trojan horse)
    AviraTR/Crypt.XPACK.Gen
    BitDefenderTrojan.FakeAlert.AVE
    Dr.WebTrojan.Packed.142
    EsetWin32/Adware.SpywareProtect2009 (application)
    FortiNetMisc/WinSpywareProtect
    F-ProtW32/Backdoor2.DTVQ
    Kasperskynot-a-virus:FraudTool.Win32.WinSpywareProtect.em
    microsoftTrojan:Win32/FakeSpypro
    normanW32/Smalltroj.LAYJ
    pandaAdware/WinSpywareProtect (spyware)
    SophosMal/UnkPack-Fam
    SymantecDownloader.MisleadApp
    Trend MicroTROJ_GEN.0Z0606
    vba32Win32.Adware.SpywareProtect2009
    V-BusterFraudtool.WinSpywareProtect.H (trojan)
    Vet (Computer Associates)
    Win32/FakeAv.ABD

    Avert® Labs has observed the following system activities:

    ActivityRisk Level
    Uses shared memory of other processes
    Low

    Other detections that have been observed.

    FileNameMcAfee Supported
    %WINDIR%\sysguard.exe
    Generic PUP.z

    System Changes

    These are general defaults for typical path variables. (Although they may differ, these examples are common.):
    %WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
    %SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
    %ProgramFiles% = \Program Files

    The following files were analyzed:

  • %USERPROFILE%\local settings\temp\25c48b3339766c08435de9d251cea0bda67e55e6.exe
  • The following files have been added to the system:

  • %WINDIR%\sysguard.exe
  • The following registry elements have been changed:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\currentversion\run\
    • sysguard = c:\windows\sysguard.exe
  • Symptoms

    Symptoms -

    This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section.

    Method of Infection

    Method of Infection -

    This is not a virus or Trojan. PUPs do not "infect" systems. They may be installed by a user individually or possibly as a part of a software package (in a bundle, for example).

    Removal -

    Removal -

    AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.

    Additional Windows ME/XP removal considerations

    Variants

    Variants -

      N/A