Home Articles Spyware Research Support Scan Now Purchase F.A.Q.

Adware/Backdoor/Downloader/SandBoxer

Alias: Peper.trojan, Adware/MemoryWatcher, SandBoxer

Description: Adware/Backdoor/Downloader/SandBoxer downloads files to victim's computer, with a help of them it will open pop-ups. It is extremely hard to detect.

Threat type:

Adware - Adware is a software application which displays advertisements on your computer. Advertisements can be displayed through pop-up / pop-under windows, additional bars or toolbars, underlined links or buttons that appear on a computer screen. Adware applications include additional code that delivers the ads. Adware authors earn money when users click on those ads. Occasionally, adware includes code that tracks user's site visits and passes it to third parties without the user's permission or knowledge.

Backdoor - A Backdoor is an undocumented or secret means that can be used to obtain unauthorized access to your computer, or a malicious program that uses such a means to penetrate a computer system. Backdoor applications exploit vulnerabilities of installed programs or operating system and allow attackers to gain control over your computer system. Backdoor works in the background and hides from the user. It is always a high security risk.

Downloader - A Downloader is a software application or part of the program which is designed to retrieve (download) and install additional files from the Internet. Malware programs often include Downloaders which allow the Malware to continually update themselves, thereby eluding detection.


Advice: Remove This is a very high risk threat and should be removed immediately as to prevent harm to your computer or your privacy.

Detection:
SpyNoMore detects Adware/Backdoor/Downloader/SandBoxer: Yes

Threat risk: High Risk
SpyNoMore AntiSpyware: Remove SandBoxer, SandBoxer Remover
Very dangerous malware. Can log user's keyboard activity and take snapshots of the user's screen. Uses stealth installation and removal is very difficult. Category includes spyware programs, adware programs and trojans.

Symptoms:

Adware/Backdoor/Downloader/SandBoxer hides from the user and stays resident in background.

Adware/Backdoor/Downloader/SandBoxer connects itself to the internet.



Adware/Backdoor/Downloader/SandBoxer Signature Details: The following information includes some of the standard signatures associated with this spyware threat. Please do not attempt to manually remove these items from your computer; Removing these items incorrectly or partially can cause your computer to experience critical errors, prevent your computer from restarting or cause loss of Internet connectivity. Should you be infected with Adware/Backdoor/Downloader/SandBoxer, you can clean your computer by downloading SpyNoMore now.

Running Process Signatures:
N/A

File Signatures:
%WINDOWS%\system32\ocn67i0.exe
%WINDOWS%\system32\unj36t.exe
%WINDOWS%\system32\zpuwldj.exe
%WINDOWS%\system32\lbk7.exe
%WINDOWS%\idjqqk.exe
%WINDOWS%\system32\mxjqzl.exe
%WINDOWS%\system32\yfk8.exe
%WINDOWS%\system32\tpws.exe
%WINDOWS%\system32\yubxk.exe
%WINDOWS%\ymcjqxfa.exe
%WINDOWS%\system32\pusy6.exe
%WINDOWS%\system32\ojz1.exe
%WINDOWS%\system32\pwbm74i.exe
%WINDOWS%\system32\gnsdk.exe
%WINDOWS%\system32\tgjog.exe
%WINDOWS%\system32\xjpvq9t0.exe
%WINDOWS%\system32\bvu9v35.exe


Registered Dll (Dynamic Link Library) Signatures:
N/A

Folder Signatures:
N/A

Registry Signatures:
HKLM\software\microsoft\windows\currentversion\app management\arpcache\memorywatcher

SpyNoMore Collected Residual File Signatures:
N/A


See Also:
Hijacker/CWS.AFF.WinShow
Hijacker/CWS.AFF.MadFinder
Hijacker/CWS.AFF.ToonComics
Hijacker/MadFinder
P2P/GnucDNA
BHO/Hijacker/PeopleOnPage.Apropos
Adware/BHO/Toolbar/WinFavorites
Dialer/Holystic
Adware/Homepage Hijacker/Downloader/Turown.a
Adware/Rads01.Quadrogram

Spyware Removal Home | Support | F.A.Q. | Contact Us | Spyware Removal Database | Privacy Policy | Site Map
Copyright © 2005-2008 Illysoft LLC