Home Malware Programs Trojans Program:Win32/Pameseg.U

Program:Win32/Pameseg.U

Posted: September 30, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 56
First Seen: May 25, 2011
Last Seen: August 16, 2020
OS(es) Affected: Windows

ProgramWin32Pameseg.U is a malicious installer application which requires PC users to send SMS messages to premium numbers in order to successfully install certain software programs and tools. ProgramWin32Pameseg.U comes bundled with certain software installation applications. Once ProgramWin32Pameseg.U is installed on the affected computer system it shows pop-up warnings and foreign language interfaces which reports the PC user that he/she should send an SMS message to a predefined number. After the affected user sends the SMS, he/she gets an activation code to activate any one of certain programs. The activation codes ProgramWin32Pameseg.U distributes after the user sends the SMS to the premium number are fake, and all of the programs ProgramWin32Pameseg.U poses to be able to activate are freeware applications. Do not ever pay to activate any of suggested programs. ProgramWin32Pameseg.U also downloads and installs additional malware threats to the compromised PC. To protect your computer from harm, uninstall ProgramWin32Pameseg.U as early as possible.

Aliases

Win32/Hoax.ArchSMS.KC [NOD32]SMSFraud.d [McAfee]Hoax/Win32.ArchSMS [Antiy-AVL]Joke/ArchSMS.hsgx.157 [AntiVir]NSIS:SMSSend-U [Avast]NSIS/Hoax.ArchSMS.G.Gen [NOD32]Artemis!F6613DC2E074 [McAfee]NirCmd [Sophos]PUA.Tool.Nirsofer.NirCmd [ClamAV]Artemis!03E4F116988E [McAfee]Hoax.Win32.ArchSMS [Ikarus]Program:Win32/Pameseg.U [Microsoft]Joke/ArchSMS.hsgx.42 [AntiVir]Trojan.SMSSend.520 [DrWeb]Hoax.Win32.ArchSMS.hsgx [Kaspersky]
More aliases (20)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



E:\Software\messenger.exe File name: messenger.exe
Size: 637.84 KB (637848 bytes)
MD5: 97b8f379b3eb62db59dce579fdd0af22
Detection count: 72
File type: Executable File
Mime Type: unknown/exe
Path: E:\Software
Group: Malware file
Last Updated: May 26, 2011
D:\messenger-b.exe File name: messenger-b.exe
Size: 638 KB (638000 bytes)
MD5: f6613dc2e0740d249a35b896acc2c46b
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: D:
Group: Malware file
Last Updated: May 27, 2011
%USERPROFILE%\Mis documentos\to??o\Messenger9.0.exe File name: Messenger9.0.exe
Size: 3.06 MB (3064879 bytes)
MD5: 6d7e702c602c5f89e4afd1ea13769a8e
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Mis documentos\to??o
Group: Malware file
Last Updated: June 6, 2011
%USERPROFILE%\Desktop\ComboFix.exe File name: ComboFix.exe
Size: 4.32 MB (4327458 bytes)
MD5: 03e4f116988e0c156246ff953c66993e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Desktop
Group: Malware file
Last Updated: August 16, 2020
Loading...