Home
Articles
Spyware Research
Support
Scan Now
Purchase
F.A.Q.
Top 25 Spyware:
Glossary Latest Detections ![]() |
RAT/SeproAlias: Backdoor.Sepro.a, Sepro
Description: The ActualNames software is an address bar search hijacker which targets IE, Netscape and AOL browsers. The ActualNames seems to contain components to interfere with the sending of mail from various applications and web sites. Bundled with KazaaMate. Suspected also to be installed by ActiveX drive-by download from some pop-ups. From the publisher: As Web users type your company?s keywords in their browser's address box, they will be taken straight to your site. Threat type: RAT - Remote Administration Tool (RAT) is a software application which provides an attacker with the capability to control your computer system remotely whenever you are online. The attacker can perform operations such as programs and/or files adding/deleting, files transfers, capturing screenshot, etc. Attacker may use captured computer for different personal needs such as to send malicious attacks. Advice: Remove This is a very high risk threat and should be removed immediately as to prevent harm to your computer or your privacy. Detection: SpyNoMore detects RAT/Sepro: Yes Threat risk: High Risk Very dangerous malware. Can log user's keyboard activity and take snapshots of the user's screen. Uses stealth installation and removal is very difficult. Category includes spyware programs, adware programs and trojans. Symptoms: Running Process Signatures: N/A File Signatures: %WINDOWS%\sepsd.bin %PROFILE%\local settings\temp\sepinst.exe %COMMON_PROGRAMS%\documents and settings\douglas\local settings\temp\sepinst.exe Registered Dll (Dynamic Link Library) Signatures: N/A Folder Signatures: %PROGRAM_FILES%\sep Registry Signatures: HKCR\sep.search.1 HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{c5183abc-eb6e-4e05-b8c9-500a16b6cf94} HKLM\software\microsoft\windows\currentversion\uninstall\sep HKCR\clsid\{c5183abc-eb6e-4e05-b8c9-500a16b6cf94} HKCU\software\sep HKCR\sep.band.1 SpyNoMore Collected Residual File Signatures: N/A
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||