veris iso_currency_code confidence targeted discovery_method cost_corrective_action security_incident

In the wild, we have seen these trojans installing the following component files in the %APPDATA% folder: appdata.dll - detected as TrojanSpy:Win32/Talsab.A dllhost.exe - detected as TrojanSpy:Win32/Talsab.A These files can be used to: Malware Type and Platform classification based on Microsoft's implementation of the Computer Antivirus Research Organization (CARO) Naming Scheme and Malware Terminology. Based on https://www.microsoft.com/en-us/security/portal/mmpc/shared/malwarenaming.aspx, https://www.microsoft.com/security/portal/mmpc/shared/glossary.aspx, https://www.microsoft.com/security/portal/mmpc/shared/objectivecriteria.aspx, and http://www.caro.org/definitions/index.html. Please start a New Thread if you're having a similar issue.View our Welcome Guide to learn how to use this site.

Malware families are extracted from Microsoft SIRs since 2008 based on https://www.microsoft.com/secur #totalhash Malware Analysis Database The JSON format can be freely reused in your application or automatically enabled in MISP taxonomy.

Added: Win.Trojan.6540730 Submission-ID: 28157768 Sender: Virus Total Sender: Anonymous Added: Win.Trojan.Wigon-404 Virus name alias: Trojan.Win32.Wigon.pqk (Kaspersky) Submission-ID: 28157773 Sender: Virus Total Sender: Anonymous Added: No Submission-ID: 28157786 Sender: Virus Total Sender:

Jan 27, 2017 In Progress Trojan Virus in folder roaming (update.jf3) mechapotato, Feb 26, 2017, in forum: Virus & Other Malware Removal Replies: 1 Views: 358 askey127 Feb 27, 2017

Top Threat behavior Installation Malware files installed by TrojanDropper:Win32/Swisyn might be embedded as resource files. http://songstersoftware.com/general/trojan-spy-win32.html Advertisements do not imply our endorsement of that product or service. The red color spreads throughout the disc to indicate whether a threat is moderate, high or severe.PreviousNextSummaryWhat to do nowTechnical informationSymptoms Symptoms System changes The following system changes may indicate the Stay logged in Sign up now!

Trojan:Win32/Swisyn.KAlert level: Severe First published: Jun 21, 2012 Latest published: Jun 09, 2016

Trojans in this family can be installed by other malware.

NOD32 probably a variant of Win32/TrojanDropper.Agent NOD32 probably unknown NewHeur_PE NOD32 Program:Win32/Winwebsec Microsoft Proxy-Agent.aj McAfee Proxy.AAQV AVG PSW.Generic6.EPP AVG Puper McAfee Puper!tr Fortinet Puper.dll McAfee Puper.dll.gen McAfee Puper.gen.h McAfee Puper.IE AVG Keys: av dnsrr email filename hash ip mutex pdb registry url useragent version Search Analysis Date2014-11-23 20:17:22MD5a3ca8239ee4a46f73d736475cddfdb7fSHA10bad7c78ee56c468b393d666370319e0672da402Static Details:File typePE32 executable for MS Windows (GUI) Intel 80386 32-bitSectionUPX0 md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709

The JSON format can be freely reused in your application or automatically enabled in MISP taxonomy. Similar Threads - Trojan Win32 Swisyn New TrojanSpy:win32 virus is on my computer please help!!