Search
Keyword: JS_PSYME
This Trojan executes when a user accesses certain websites where it is hosted. This is the Trend Micro detection for Web pages that were compromised through the insertion of a certain IFRAME tag. It
{8D121F0E-DD71-419D-B363-B008D4BE8476} %User Temp%\~zm_{8D121F0E-DD71-419D-B363-B008D4BE8476}\css %User Temp%\~zm_{8D121F0E-DD71-419D-B363-B008D4BE8476}\images %User Temp%\~zm_{8D121F0E-DD71-419D-B363-B008D4BE8476}\js (Note: %User Temp%
{39285E50-72B9-4EBA-BB36-4204B4438777} %User Temp%\~zm_{39285E50-72B9-4EBA-BB36-4204B4438777}\css %User Temp%\~zm_{39285E50-72B9-4EBA-BB36-4204B4438777}\images %User Temp%\~zm_{39285E50-72B9-4EBA-BB36-4204B4438777}\js (Note: %User Temp%
{B3E47B04-71C9-4887-978A-C7B73D705D72} %User Temp%\~zm_{B3E47B04-71C9-4887-978A-C7B73D705D72}\css %User Temp%\~zm_{B3E47B04-71C9-4887-978A-C7B73D705D72}\images %User Temp%\~zm_{B3E47B04-71C9-4887-978A-C7B73D705D72}\js (Note: %User Temp%
{04C7E7A4-EFAF-495F-9B61-68F0EF38BA19} %User Temp%\~zm_{04C7E7A4-EFAF-495F-9B61-68F0EF38BA19}\css %User Temp%\~zm_{04C7E7A4-EFAF-495F-9B61-68F0EF38BA19}\images %User Temp%\~zm_{04C7E7A4-EFAF-495F-9B61-68F0EF38BA19}\js (Note: %User Temp%
{DC3270CF-CE42-4DFE-A515-B3E5DF8B8BB2} %User Temp%\~zm_{DC3270CF-CE42-4DFE-A515-B3E5DF8B8BB2}\css %User Temp%\~zm_{DC3270CF-CE42-4DFE-A515-B3E5DF8B8BB2}\images %User Temp%\~zm_{DC3270CF-CE42-4DFE-A515-B3E5DF8B8BB2}\js (Note: %User Temp%
{5A6C0D54-E2F2-4ABB-B2D3-7C7BC9B804C5} %User Temp%\~zm_{5A6C0D54-E2F2-4ABB-B2D3-7C7BC9B804C5}\css %User Temp%\~zm_{5A6C0D54-E2F2-4ABB-B2D3-7C7BC9B804C5}\images %User Temp%\~zm_{5A6C0D54-E2F2-4ABB-B2D3-7C7BC9B804C5}\js (Note: %User Temp%
{46A05B4E-923D-4310-9E03-2C1765332E20}\js %User Temp%\~zm_{46A05B4E-923D-4310-9E03-2C1765332E20} %User Temp%\~zm_{46A05B4E-923D-4310-9E03-2C1765332E20}\css %User Temp%\~zm_{46A05B4E-923D-4310-9E03-2C1765332E20}\images (Note: %User Temp%
\icons %User Temp%\~zm_{C6B674EE-5539-4B47-94BA-46A998DA5880}\js %User Temp%\~zm_{C6B674EE-5539-4B47-94BA-46A998DA5880}\js\bramus %User Temp%\~zm_{C6B674EE-5539-4B47-94BA-46A998DA5880}\js\prototype (Note:
{730BE1A4-1263-4096-917C-4484264E4FD6} %User Temp%\~zm_{730BE1A4-1263-4096-917C-4484264E4FD6}\css %User Temp%\~zm_{730BE1A4-1263-4096-917C-4484264E4FD6}\images %User Temp%\~zm_{730BE1A4-1263-4096-917C-4484264E4FD6}\js (Note: %User Temp%
{33AA21EC-0661-41EF-9034-F8CC1BA8CD39} %User Temp%\~zm_{33AA21EC-0661-41EF-9034-F8CC1BA8CD39}\css %User Temp%\~zm_{33AA21EC-0661-41EF-9034-F8CC1BA8CD39}\images %User Temp%\~zm_{33AA21EC-0661-41EF-9034-F8CC1BA8CD39}\js (Note: %User Temp%
\images %User Temp%\7023104\images\icons %User Temp%\7023104\images\bramus %User Temp%\7023104\js %User Temp%\7023104\js\bramus %User Temp%\7023104\js\prototype (Note: %User Temp% is the current user's Temp
user: Upon execution of this malicious embedded JS file, it displays the following message box to trick the user: It does not have rootkit capabilities. It does not exploit any vulnerability.
This Adware may arrive bundled with malware packages as a malware component. It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting
and will execute its routine upon activation by the user: Upon execution of this malicious embedded JS file, it displays the following message box to trick the user: JS/TrojanDownloader.Agent.QHW trojan
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users. It arrives on a system as a file dropped by other malware or as a file downloaded
activation by the user: Upon execution of this malicious embedded JS file, it displays the following message box to trick the user: It does not have rootkit capabilities. It does not exploit any vulnerability.
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. Arrival Details This Trojan arrives on a system as a
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It deletes the initially executed copy of itself.
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. Arrival Details This Trojan arrives on a system as a