Home Malware Programs Trojans Program:Win32/Pameseg.H

Program:Win32/Pameseg.H

Posted: June 19, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 35
First Seen: October 25, 2011
Last Seen: June 13, 2021
OS(es) Affected: Windows

Program:Win32/Pameseg.H is a Trojan that tries to steal money from unsuspecting computer users. Program:Win32/Pameseg.H attempts to urge victims to send a text message to a provided number, that would later ask installing a particular software product, which is, of course, paid. Program:Win32/Pameseg.H displays a fake pop-up notification on the affected PC's screen created in French. The malicious software program states that it will install an MSN messenger, Internet Explorer, Adobe Flash Player, VLC Player, Windows Media Player, OpenOffice, Outlook Express, Counter Strike, Avira Antivirus, Audacity and many other programs, but if you follow its instructions you will see that the messenger you are preparing to install needs an activation code that will only be received after you send out a text message to the provided number. Once executed, Program:Win32/Pameseg.H asks you to select a certain application you want to install. Then, the affected computer users has to agree with the terms and conditions, and finally, only after he/she sends the SMS, the supposed code is received that would allegedly enable victims to completely install the particular application. Alo, Program:Win32/Pameseg.H can change your web browser homepage to unwillingly divert you to one of its websites named wiiqi.com, pucuy.com or yaape.com.

Aliases

NSIS:Downloader-HP [GData]Program:Win32/Pameseg.H [Microsoft]TR/BegSMS.A [AntiVir]Win32.NSISHoax.ArchS [eSafe]NSIS:Downloader-HP [Trj] [Avast]Trojan.ADH [Symantec]VBS/StartPage.NDC [NOD32]Riskware [K7AntiVirus]Generic StartPage!or [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\ARCHIVES_PC4\Archives_Phil_pour_Denis\User_Denis\2011_11_24_Sauvegardes_Mail_PC1\LOGICIEL TELECHARGER\install_openoffice_clic.exe File name: install_openoffice_clic.exe
Size: 149.43 KB (149439 bytes)
MD5: 97f4d972f907b5f7d6fb7d717f649f7d
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: C:\ARCHIVES_PC4\Archives_Phil_pour_Denis\User_Denis\2011_11_24_Sauvegardes_Mail_PC1\LOGICIEL TELECHARGER\install_openoffice_clic.exe
Group: Malware file
Last Updated: June 13, 2021

Additional Information

The following messages's were detected:
# Message
1'Pour obtenir votre code d’activation, veuillez envoyer depuis votre portable un SMS au numero 81015 avec le mot LP.'
2'To obtain your activation code, please send an SMS from your cellphone number to 81015 with the word LP.'

Loading...