Home Malware Programs Trojans Program:Win32/PowerRegScheduler

Program:Win32/PowerRegScheduler

Posted: July 8, 2010

Threat Metric

Ranking: 1,937
Threat Level: 1/10
Infected PCs: 4,094
First Seen: December 23, 2010
Last Seen: October 16, 2023
OS(es) Affected: Windows

Program:Win32/PowerRegScheduler is spyware which targets the Windows platform. Program:Win32/PowerRegScheduler changes configurations to give hackers access to files on the compromised computer. Program:Win32/PowerRegScheduler may also alter the Windows directory and download corrupt files from external servers. Program:Win32/PowerRegScheduler has the ability to monitor user activities to obtain valuable information, specifically login details. Program:Win32/PowerRegScheduler is a dangerous threat to any computer and should be terminated immediately.

Aliases

Trojan/Win32.Muwid [AhnLab-V3]PAK_Generic.001 [TrendMicro]BackDoor.Crutch.origin [DrWeb]Artemis!A3300908EA6C [McAfee]Suspicious file [Panda]Win32.SuspectCrc [Ikarus]Program:Win32/PowerRegScheduler [Microsoft]Virus in password protected archive [eSafe]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\jtFTP\PalmDesktopSetup.exe File name: PalmDesktopSetup.exe
Size: 15.41 MB (15419976 bytes)
MD5: 12ab0e4abe34fc252301ccacd7ab4581
Detection count: 361
File type: Executable File
Mime Type: unknown/exe
Path: C:\jtFTP
Group: Malware file
Last Updated: March 6, 2023
%WINDIR%\system32\config\systemprofile\Impostazioni locali\Dati applicazioni\Windows Internet Name Service\wins.exe File name: wins.exe
Size: 4.6 MB (4603904 bytes)
MD5: a3300908ea6c58551c8a2ae704658244
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\config\systemprofile\Impostazioni locali\Dati applicazioni\Windows Internet Name Service
Group: Malware file
Last Updated: December 28, 2010
Loading...