Threat Search: 

ThreatExpert's Statistics for Generic PUP.z [McAfee]:

Generic PUP.z [McAfee] is also known as:
Threat AliasNumber of Incidents
Trojan.Fakeavalert [Symantec]745
not-a-virus:FraudTool.Win32.UltimateAntivirus.cf [Kaspersky Lab]645
not-a-virus:FraudTool.Win32.SpywarePreventer.u [Kaspersky Lab]644
FirePass [Symantec]529
not-a-virus:PSWTool.Win32.FirePass.dv [Kaspersky Lab]529
Dropper/Agent.81932 [AhnLab]437
PSWTool.FirePass!sd6 [PC Tools]345
Trojan.Fakeavalert!sd6 [PC Tools]292
Generic.Win32.Malware.FakeAlert.N [Ikarus]130
Adware.NetPumper [PC Tools]117
not-a-virus:PSWTool.Win32.NetPass.fv [Kaspersky Lab]99
NetPumper [Symantec]90
not-a-virus:FraudTool.Win32.Agent.cd [Kaspersky Lab]90
SoftwareBundler:Win32/NetPumper [Microsoft]90
Troj/FakeAle-FJ [Sophos]90
Win-Trojan/Xema.variant [AhnLab]90
Hacktool [Symantec]80
not-a-virus:FraudTool.Win32.Agent.cc [Kaspersky Lab]77
Downloader.MisleadApp [Symantec]75
AntiVirus2008 [Symantec]71
PWSTool.FirePass!sd6 [PC Tools]69
Virus.Win32.Rootkit [Ikarus]66
not-a-virus:PSWTool.Win32.NetPass [Ikarus]64
Trojan-Downloader.MisleadApp!sd6 [PC Tools]57
not-a-virus:AdWare.Win32.Relevant.i [Ikarus]56
Mal/Heuri-E, Mal/Emogen-N [Sophos]50
not-a-virus:AdWare.Win32.BHO.ebb [Kaspersky Lab]49
Troj/FakeAV-DC [Sophos]49
Trojan:Win32/MotePro [Microsoft]49
Trojan-Spy.Win32.Mslagent [Ikarus]49
VirusResponseLab [Symantec]49
not-a-virus:FraudTool.Win32.XPSecurityCenter.bk [Kaspersky Lab]48
Trojan.Win32.Monder.bdnr [Kaspersky Lab]48
Adware.BHO!sd6 [PC Tools]47
Mal/Generic-A [Sophos]45
not-a-virus:AdWare.Win32.BHO.efr [Kaspersky Lab]45
not-a-virus:AdWare.Win32.CashDeluxe [Ikarus]45
Program:Win32/FakeAlert.N [Microsoft]44
Adware.Websearch [Symantec]42
Adware.Begin2search [Symantec]40
New Malware.aj [McAfee]39
Program:Win32/Antivirus2009 [Microsoft]36
Trojan.Vundo [Symantec]36
Trojan Horse [Symantec]31
RogueAntiSpyware.VirusResponseLab [PC Tools]30
Trojan.Dropper [Symantec]30
PWSTool.NetPass!sd6 [PC Tools]27
Trojan.Win32.Agent.asjk [Kaspersky Lab]26
Virus.Trojan.Win32.Agent.abpb [Ikarus]25
Adware:Win32/AdRotator [Microsoft]24
Generic.Win32.Malware [Ikarus]22
Trojan.Zlob [Ikarus]22
Adware.Gen [Symantec]21
BrowserModifier:Win32/Fotomoto [Microsoft]21
Mal/EncPk-CZ [Sophos]21
not-a-virus:FraudTool.Win32.Drpcclean [Ikarus]21
not-a-virus:FraudTool.Win32.VirusProtectPro.ak [Kaspersky Lab]21
Troj/FakeAle-JO [Sophos]21
TROJ_FAKEAV.UF [Trend Micro]21
Trojan.Rogue.VirLab.A [Ikarus]21
Trojan.Adclicker [Symantec]20
Downloader [Symantec]19
PSWTool.NetPass!sd6 [PC Tools]18
Trojan.Advatrix [Symantec]18
Trojan-Dropper.Agent [Ikarus]17
Adware.MyCentria [Symantec]16
not-a-virus:FraudTool.Win32.SpywarePreventer.y [Kaspersky Lab]16
not-a-virus:NetTool.Win32.Netcut.a [Kaspersky Lab]16
not-a-virus:RiskTool.Win32.Squnsh.b [Kaspersky Lab]16
not-a-virus:Server-Proxy.Win32.3proxy.bo [Kaspersky Lab]16
Troj/FakeVir-HO [Sophos]16
Trojan.Win32.Agent [Ikarus]16
BHO.Win32.Fotomoto [Ikarus]15
Program:Win32/FakeASC [Microsoft]15
Program:Win32/TinyProxy [Microsoft]15
FakeAlert-BO [McAfee]14
not-a-virus:AdWare.Win32.Relevant.i [Kaspersky Lab]14
Rootkit.Win32.TDSS [Ikarus]14
W32.Spybot.Worm [Symantec]14
Win32.SuspectCrc [Ikarus]14
TrojanDownloader:Win32/Renos.DU [Microsoft]13
Virus.Win32.Spyware [Ikarus]13
FakeAlert-BO.dll [McAfee]12
Mal/EncPk-HJ [Sophos]12
not-a-virus:AdWare.Win32.Agent.kip [Kaspersky Lab]12
RiskTool.Squnsh.A [PC Tools]12
TrojanDownloader:Win32/Fakeinit [Microsoft]12
Virus.Win32.AdWare [Ikarus]12
Adware.Fotomoto [PC Tools]11
Trojan.Fakeav [Ikarus]11
AdWare.FearAds [Ikarus]10
Adware:Win32/Mysidesearch [Microsoft]10
AntiVirus2009 [Symantec]10
Downloader.BaiduBar [Ikarus]10
not-a-virus:Client-IRC.Win32.mIRC.603 [Kaspersky Lab]10
Packed.Generic.187 [Symantec]10
Adware.Begin2search [PC Tools]9
AntiVirProtect [Symantec]9
Generic.Adw.Rotator [Ikarus]9
not-a-virus:FraudTool.Win32.SpywareGuard2008.al [Kaspersky Lab]9

Generic PUP.z [McAfee] has the following possible countries of origin:
OriginNumber of Incidents
Russian Federation777
China78
Israel23
United Kingdom21
Republic of Korea19
Ukraine17
Canada5
Chile4
Germany4
Brazil3
Japan2
South Africa2
Taiwan2
France1
Italy1
Spain1

Generic PUP.z [McAfee] is known to be created as:
%AppData%\psvr32.exe
%AppData%\xfctbsptco.exe
%DownloadedProgramFiles%\xmlparse_.dll
%LocalSettings%\tempimages\si1setup-160-si1prt1.exe
%ProgramFiles%\3721\assist\asfsks.dll
%ProgramFiles%\3721\assist\assist.dll
%ProgramFiles%\3721\assist\eheflash.dll
%ProgramFiles%\3721\assist\repair.dll
%ProgramFiles%\adstechnology\adstechnology.exe
%ProgramFiles%\adware_pro\apengine.dll
%ProgramFiles%\allsm\myhook.dll
%ProgramFiles%\allsm\nvsvc16.exe
%ProgramFiles%\amazon toolbar\amazon.dll
%ProgramFiles%\antimalware_pro\apengine.dll
%ProgramFiles%\antimalwareguard\amg.exe
%ProgramFiles%\antimalwarepro\ssengine.dll
%ProgramFiles%\antimalwarepro\startapp.exe
%ProgramFiles%\antimalwaresuite\pp.exe
%ProgramFiles%\antispyknight\antispyknight.exe
%ProgramFiles%\antispywareexpert\ase_jp.exe
%ProgramFiles%\antispywarexp2009\uninstall.exe
%ProgramFiles%\anvtrgrsoftware\uninst.exe
%ProgramFiles%\aspmonitor\hk.dll
%ProgramFiles%\aspmonitor\settings.exe
%ProgramFiles%\avirtrsoftware\uninst.exe
%ProgramFiles%\baidu\iexp\bdsrhook.dll
%ProgramFiles%\baidu\iexp\tmp\bdsrhook.dll
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\bittorrent fastest tool\bitp.exe
%ProgramFiles%\cheat engine\dbk32.sys
%ProgramFiles%\cnnic\cdn\cdnunins.exe
%ProgramFiles%\dfdsfs\kiss.exe
%ProgramFiles%\drpcclean\drpcmain.exe
%ProgramFiles%\drpcclean\drpcmd.exe
%ProgramFiles%\drpcclean\drpctrans.exe
%ProgramFiles%\elcomsoft\pspr\psprserv.exe
%ProgramFiles%\ezt\poinstallnew.exe
%ProgramFiles%\fieryads\commlayer.dll
%ProgramFiles%\fieryads\fieryads.dll
%ProgramFiles%\fsdfs\kiss.exe
%ProgramFiles%\internet explorer\setupapi.dll
%ProgramFiles%\kwssolution\kwsguide.exe
%ProgramFiles%\mail passview\mailpv.exe
%ProgramFiles%\megauploadtoolbar\megauploadtoolbar.dll
%ProgramFiles%\messenger detect\mdserv.exe
%ProgramFiles%\messenger detect\mdsniffer.exe
%ProgramFiles%\messenger detect\messengerdetect.exe
%ProgramFiles%\microav\microav.exe
%ProgramFiles%\msds solutions\toolbar\msdstoolbar.dll
%ProgramFiles%\msvideoplugin\80_18.exe
%ProgramFiles%\mysearch\bar\1.bin\s4bar.dll
%ProgramFiles%\ndp\pup.exe
%ProgramFiles%\netcut\netcut.exe
%ProgramFiles%\netpumper\shutdown.exe
%ProgramFiles%\nirsoft\password recovery package\astlog.exe
%ProgramFiles%\nirsoft\password recovery package\passwordfox.exe
%ProgramFiles%\onestepsearch\osopt.exe
%ProgramFiles%\pchealthcenter\1.exe
%ProgramFiles%\pchealthcenter\2.exe
%ProgramFiles%\peoplepc\toolbar\ppctoolbar.dll
%ProgramFiles%\pointgo\pointgo.dll
%ProgramFiles%\pointway\controlpointway.exe
%ProgramFiles%\power search tool\powersearchtool4_0.dll
%ProgramFiles%\pst\powersearchtool4.dll
%ProgramFiles%\pstpassword\pstpassword.exe
%ProgramFiles%\pwx\pwx.exe
%ProgramFiles%\qyule\unins000.exe
%ProgramFiles%\regfixpro\tcl.dll
%ProgramFiles%\sdfsdfs\kiss.exe
%ProgramFiles%\shopguide\shpsv.dll
%ProgramFiles%\sixsigmatoolbar\sixsigmatoolbar.dll
%ProgramFiles%\smart keystroke recorder\sma.exe
%ProgramFiles%\spydajaba\sdjbdel.exe
%ProgramFiles%\spydajaba\sdjbtrans.exe
%ProgramFiles%\spyfighter\spyfighter.exe
%ProgramFiles%\spyware guard 2008\spywareguard.exe
%ProgramFiles%\spyware guard 2008\uninstall.exe
%ProgramFiles%\sysguarder\sysguarder.exe
%ProgramFiles%\system guard 2009\systemguard.exe
%ProgramFiles%\toolbar888\uninst.exe
%ProgramFiles%\totalvirusprotection\webmonitor.exe
%ProgramFiles%\videocacheview\videocacheview.exe
%ProgramFiles%\virslab\uninst.exe
%ProgramFiles%\virslab\virslabwarning.dll
%ProgramFiles%\wav\wav.exe
%ProgramFiles%\winantiviruspro3.8\winantiviruspro.exe
%ProgramFiles%\xlguarder\gmon.exe
%ProgramFiles%\xp_antispyware\uninstall.exe
%ProgramFiles%\zcomprdiy\zcomprdiy.exe
%ProgramFiles%\zztoolbar\uninstall.exe
%Programs%\startup\userinit.exe
%System%\amovid.dll
%System%\av.dll
%System%\avid.dll
%System%\cenmjauorekm.dll
%System%\commlayer.dll
%System%\drive2\gsv33o21.exe
%System%\drivers\appngmts.sys
%System%\drivers\services.exe
%System%\ejlsofuvvppg.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %DownloadedProgramFiles% is a variable that refers to the file system directory containing downloaded program files. A typical path is C:\Windows\Downloaded Program Files.
  • %LocalSettings% is a variable that specifies the current user's local settings folder. By default, this is C:\Documents and Settings\[UserName]\Local Settings (Windows NT/2000/XP).
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %Programs% is a variable that refers to the file system directory that contains the user's program groups. A typical path is C:\Documents and Settings\[UserName]\Start Menu\Programs.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).