Threat Search: 

ThreatExpert's Statistics for PWCrack-Winspy [McAfee]:

PWCrack-Winspy [McAfee] is also known as:
Threat AliasNumber of Incidents
not-a-virus:FraudTool.Win32.WinSpywareProtect.eo [Kaspersky Lab]702
Troj/FakeAV-KM [Sophos]702
SpywareProtect2009 [Symantec]676
Virus.Win32.AdWare [Ikarus]624
Trojan Horse [Symantec]142
Trojan-Spy.Win32.WinSpy.aa [Kaspersky Lab]87
Trojan.Whispy!sd5 [PC Tools]84
Trojan.Win32.Whispy.a [Kaspersky Lab]84
Virus.Win32.Agent.KGP [Ikarus]75
Spyware.BCWinSpy [Symantec]71
RogueAntiSpyware.WinSpywareProtect [PC Tools]52
Trojan-Spy.WinSpy!sd5 [PC Tools]42
TSPY_WINSPY.H [Trend Micro]37
Spyware.WinSpy [Symantec]35
Trojan-Spy.Win32.WinSpy.ae [Kaspersky Lab]31
Application.WinSpy_Stealth_Monitor [PC Tools]29
RogueAntiSpyware.Sysguard [PC Tools]26
Mal/Generic-A [Sophos]23
Trojan-Spy.Win32.WinSpy.a [Kaspersky Lab]21
not-a-virus:Monitor.Win32.WinSpy.l [Kaspersky Lab]18
TROJ_WINSPY.AN [Trend Micro]16
TrojanSpy.WinSpy.DPE [PC Tools]16
TrojanSpy.WinSpy.DPS [PC Tools]16
Trojan-Spy.Win32.WinSpy.ae [Ikarus]10
MonitoringTool:Win32/Winspy [Microsoft]8
TrojanSpy.WinSpy.DRF [PC Tools]8
TrojanSpy:Win32/Winspy [Microsoft]8
Trojan-Spy.Win32.WinSpy.ag [Kaspersky Lab]7
Backdoor.Win32.VB.bal [Kaspersky Lab]5
Spyware.WinSpy!sd5 [PC Tools]5
Trojan-Spy.Win32.WinSpy [Ikarus]5
TrojanSpy:Win32/Winspy.AA [Microsoft]5
Hacktool [Symantec]4
Mal/EncPk-FX [Sophos]4
not-a-virus:Monitor.Win32.WinSpy.o [Kaspersky Lab]4
Packed.Generic.187 [Symantec]4
Spyware.BCWinSpy!sd6 [PC Tools]4
Troj/WinSpy-K [Sophos]4
Trojan-Spy.KeyLogger!sd5 [PC Tools]4
Trojan-Spy.Win32.KeyLogger.mj [Kaspersky Lab]4
Backdoor.Trojan [Symantec]3
Backdoor.VB!sd5 [PC Tools]3
Trojan-Spy.Win32.WinSpy.ai [Kaspersky Lab]3
Trojan-Spy.Win32.WinSpy.c [Kaspersky Lab]3
Trojan-Spy.Win32.WinSpy.g [Ikarus]3
AntispywareProXP [Symantec]2
Backdoor:Win32/VB [Microsoft]2
Generic.Win32.Malware.WinSpywareProtect [Ikarus]2
Infostealer [Symantec]2
TR.HackTool.Govt [Ikarus]2
Troj/WinSpy-M [Sophos]2
TROJ_FAKEAV.AJ [Trend Micro]2
TROJ_VB.CRT [Trend Micro]2
TROJ_VB.CRU [Trend Micro]2
TROJ_WINSPYRMK.A [Trend Micro]2
Trojan-Spy.Win32.WinSpy.ar [Kaspersky Lab]2
Trojan-Spy.Win32.WinSpy.bn [Kaspersky Lab]2
Trojan-Spy.Win32.WinSpy.n [Kaspersky Lab]2
Trojan-Spy.Win32.WinSpy.pt [Kaspersky Lab]2
Trojan-Spy.Win32.WinSpy.qb [Kaspersky Lab]2
Trojan-Spy.Win32.WinSpy.r [Kaspersky Lab]2
TrojanSpy.WinSpy.DQD [PC Tools]2
TrojanSpy:Win32/Keylogger [Microsoft]2
TSPY_WINSPY.AJ [Trend Micro]2
TSPY_WINSPY.AP [Trend Micro]2
Win-Trojan/Hacktool.272384 [AhnLab]2
Win-Trojan/Winspy.36864 [AhnLab]2
Backdoor.Win32.Omega.a [Ikarus]1
Backdoor.Win32.VB.ve [Kaspersky Lab]1
Backdoor.Win32.VB.yu [Kaspersky Lab]1
Mal/EncPk-GE, Mal/EncPk-FX [Sophos]1
not-a-virus:FraudTool.Win32.AntiVirusPro.es [Kaspersky Lab]1
not-a-virus:Monitor.Win32.WinSpy.88 [Kaspersky Lab]1
not-a-virus:Monitor.Win32.WinSpy.c [Kaspersky Lab]1
not-a-virus:Monitor.Win32.WinSpy.k [Kaspersky Lab]1
not-a-virus:Monitor.Win32.WinSpy.v [Kaspersky Lab]1
not-a-virus:Monitor.Win32.WinSpy.x [Kaspersky Lab]1
Troj/FakeVir-GY [Sophos]1
Troj/ScrCpt-Gen [Sophos]1
TROJ_SHEUR.QI [Trend Micro]1
Trojan.DL.FraudLoad.CN.Gen [PC Tools]1
Trojan.DL.FraudLoad.DC [PC Tools]1
Trojan.Fakealert [Ikarus]1
Trojan.Fakealert.ads.1 [Ikarus]1
Trojan.Win32.Agent [Ikarus]1
Trojan.Win32.Agent.amgg [Kaspersky Lab]1
Trojan.Win32.FraudPack [Ikarus]1
Trojan.Win32.FraudPack.gyq [Kaspersky Lab]1
Trojan.Win32.FraudPack.hyk [Kaspersky Lab]1
Trojan:Win32/WinSpywareProtect [Microsoft]1
Trojan-Downloader.Win32.FraudLoad.cvo [Kaspersky Lab]1
Trojan-Spy.VB!sd5 [PC Tools]1
Trojan-Spy.Win32.VB.ec [Kaspersky Lab]1
Trojan-Spy.Win32.VB.gj [Kaspersky Lab]1
Trojan-Spy.Win32.WinSpy.aav [Kaspersky Lab]1
Trojan-Spy.Win32.WinSpy.ak [Kaspersky Lab]1
Trojan-Spy.Win32.WinSpy.bi [Kaspersky Lab]1
Trojan-Spy.Win32.WinSpy.dq [Kaspersky Lab]1
Trojan-Spy.Win32.WinSpy.eo [Kaspersky Lab]1
Trojan-Spy.Win32.WinSpy.fh [Kaspersky Lab]1

PWCrack-Winspy [McAfee] has the following possible countries of origin:
OriginNumber of Incidents
Germany1
Russian Federation1

PWCrack-Winspy [McAfee] is known to be created as:
%System%\ansmtp.dll
%System%\aosmtp.dll
%System%\iehelper.dll
%System%\winhandler.dll
%Temp%\9aa6fa49.exe
%Temp%\compress0\ansmtp.dll
%Temp%\compress0\desktop.exe
%Temp%\compress0\hpeg.dll
%Temp%\compress0\ij12.exe
%Temp%\compress0\msn.exe
%Temp%\compress0\outlook.exe
%Temp%\compress0\rsver.dll
%Temp%\compress0\services.exe
%Temp%\compress0\setup1.exe
%Temp%\compress0\sm.exe
%Temp%\compress0\taskmgr.exe
%Temp%\compress0\uninse.exe
%Temp%\compress0\unir.exe
%Temp%\compress0\winsyst.exe
%Temp%\compress0\winsyst32.exe
%Temp%\compress0\winup32.exe
%Temp%\lowpower.exe
%Temp%\lprn32.exe
%Temp%\uns12.exe
%Temp%\wzse0.tmp\ansmtp.dll
%Temp%\wzse0.tmp\rsver.dll
%Temp%\wzse0.tmp\setup1.exe
%Windir%\auto32.exe
%Windir%\comp.exe
%Windir%\csrss.exe
%Windir%\data\csrss.exe
%Windir%\data\services.exe
%Windir%\debug64\services.exe
%Windir%\display\services.exe
%Windir%\display\smss.exe
%Windir%\dll32.exe
%Windir%\enco.exe
%Windir%\encod.exe
%Windir%\hpeg.dll
%Windir%\img32\csrss.exe
%Windir%\img32\services.exe
%Windir%\isas\smss.exe
%Windir%\misi.exe
%Windir%\msim32.exe
%Windir%\msimn.exe
%Windir%\msn64.exe
%Windir%\netcom.exe
%Windir%\netcox.exe
%Windir%\ompx.exe
%Windir%\osdebug\services.exe
%Windir%\outlook.exe
%Windir%\outlook32.exe
%Windir%\outlookexpress.exe
%Windir%\rpool\services.exe
%Windir%\rsver.dll
%Windir%\sm.exe
%Windir%\taskmgr.exe
%Windir%\uninse.exe
%Windir%\winhandler.dll
%Windir%\winup32.exe
%Windir%\winusers.exe
%Windir%\winvid.exe
%Windir%\zip\csrss.exe
%Windir%\zip\services.exe
%Windir%\ziplogs\csrss.exe
%Windir%\ziplogs\services.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.