| Visit ThreatExpert web site | | | Close Report |
[PCTools]
[Symantec]
[Kaspersky Lab]
[Sophos]
[AhnLab]| What's been found | Severity Level |
| Capability to send out email message(s) with the built-in SMTP client engine. | ![]() |
| Contains characteristics of an identified security risk. | ![]() |
![]() | Possible Security Risk |
| Security Risk | Description |
PSWTool.MailPassView!sd6![]() |
PSWTool.MailPassView!sd6 is a potentially unsafe program designed to access the passwords in your system. |
| Threat Category | Description |
![]() |
A hacktool that could be used by attackers to break into a system |
![]() |
A keylogger program that can capture all user keystrokes (including confidential details such username, password, credit card number, etc.) |
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash | Alias |
| 1 | c:\%ComputerName%.txt | 0 bytes | MD5: 0xD41D8CD98F00B204E9800998ECF8427E SHA-1: 0xDA39A3EE5E6B4B0D3255BFEF95601890AFD80709 |
(not available) |
| 2 | %System%\h4714log.txt | 140 bytes | MD5: 0xE101D0AF75AFD4A96DC5C4AD0052D66A SHA-1: 0x12A38A87A982092C9DAF581BA9AAA038047B9F22 |
(not available) |
| 3 |
%System%\owner.exe
|
88,576 bytes | MD5: 0xBB5208189F45564AF76D7810A2E8B59C SHA-1: 0x76B9A6311C8A55FC5E9E3EEC7878F64C36291491 |
PWSTool.MailPassView!sd6 [PCTools]Hacktool [Symantec]not-a-virus:PSWTool.Win32.MailPassView.as [Kaspersky Lab]Generic PWS.y!q [McAfee]HackTool:Win32/Mailpassview [Microsoft] |
| 4 | [file and pathname of the sample #1] | 632,320 bytes | MD5: 0x3CE50D5A0CC4AED6338DAA9F56433F02 SHA-1: 0x458D7B5996F846F8E86F074947D1DE086D7B22A2 |
Trojan-PSW.Generic [PCTools]Infostealer [Symantec]not-a-virus:PSWTool.Win32.MailPassView.ck [Kaspersky Lab]Mal/Banspy-F [Sophos]Dropper/MailPass.632320 [AhnLab] |
| 5 | c:\winhelp.txt | 350 bytes | MD5: 0xD85014068F786AF79A2682462DAE8500 SHA-1: 0xA4C9CF556401E9C2E635E2CA7CB7F63756FB4E62 |
(not available) |
| 6 | c:\winx.log | 138 bytes | MD5: 0x55CE55C10C0CB60721763D56D952FC3A SHA-1: 0x908C5BFF10FDF26C736A8ED20D488D3808C38CD9 |
(not available) |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
owner.exe![]() | %System%\owner.exe![]() | 102,400 bytes |
| [filename of the sample #1] | [file and pathname of the sample #1] | 655,360 bytes |
![]() | Other details |
![]() |
Israel |
![]() |
Brazil |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.
The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2010 ThreatExpert. All rights reserved.