Home Malware Programs Rogue Anti-Spyware Programs SpyDawn

SpyDawn

Posted: February 14, 2007

Threat Metric

Threat Level: 10/10
Infected PCs: 52
First Seen: July 24, 2009
Last Seen: January 23, 2022
OS(es) Affected: Windows

ScreenshotSpyDawn, a clone of VirusBurst and SpyCrush, is a rogue anti-spyware program that may download and install without your knowledge or consent through a Trojan. SpyDawn pops up fake security alerts on your taskbar in order to trick you into purchasing their software. SpyDawn may also download and install other unwanted software without your permission.

Aliases

Spyware.SpyDawn [Prevx1]not-a-virus:FraudTool.Win32.SpyHeal.a [Kaspersky]Adware.SpyHeal.D [BitDefender]Potentially harmful program Fake_AntiSpyware.P [AVG]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



geplxss.dll File name: geplxss.dll
Size: 11.77 KB (11776 bytes)
MD5: bb33d3dc0213d8e61ccfc6ee5db35032
Detection count: 37
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
tvomnc.dll File name: tvomnc.dll
Size: 11.77 KB (11776 bytes)
MD5: 6302642bef11ba75d522dd9f22553fdc
Detection count: 28
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
SpyDawn.exe File name: SpyDawn.exe
Size: 1.79 MB (1794048 bytes)
MD5: b1355ed22034d8b8e1227f040103d874
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 11, 2019

Registry Modifications

The following newly produced Registry Values are:

CLSID{63948A86-9227-4DAB-8AA6-CCD2111264A0}{7DE844A5-DC96-4CD5-B4EE-1C7AE0B5E62A}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SpyDawn
Loading...