O.P. WLM Safe 4.0 - What is this!
I just downloaded this new Script called: WLM-Safe-4.0.plsc
There is not much info about and what it does when checking on their website with the name: wlm-safe.uptodown.com
One of the names on this site is "uptodown". To me is it similar to "downdup" that is a very wellknown Trojan.
I just checked the .plsc file on VirusTotal (http://www.virustotal.com/analisis/6c600ae61efd52212f865dbbb19aa287)
And it found this:
a-squared 4.0.0.93 2009.02.09 -
AhnLab-V3 5.0.0.2 2009.02.09 -
AntiVir 7.9.0.76 2009.02.09 -
Authentium 5.1.0.4 2009.02.08 -
Avast 4.8.1335.0 2009.02.09 -
AVG 8.0.0.229 2009.02.09 -
BitDefender 7.2 2009.02.09 -
CAT-QuickHeal 10.00 2009.02.09 -
ClamAV 0.94.1 2009.02.09 -
Comodo 972 2009.02.09 -
DrWeb 4.44.0.09170 2009.02.09 Tool.Prockill
eSafe 7.0.17.0 2009.02.09 Win32.Banker
eTrust-Vet 31.6.6347 2009.02.09 -
F-Prot 4.4.4.56 2009.02.09 -
F-Secure 8.0.14470.0 2009.02.09 -
Fortinet 3.117.0.0 2009.02.09 -
GData 19 2009.02.09 -
Ikarus T3.1.1.45.0 2009.02.09 -
K7AntiVirus 7.10.624 2009.02.09 -
Kaspersky 7.0.0.125 2009.02.09 -
McAfee 5520 2009.02.08 potentially unwanted program PrcViewer
McAfee+Artemis 5521 2009.02.09 potentially unwanted program PrcViewer
Microsoft 1.4306 2009.02.09 -
NOD32 3839 2009.02.09 Win32/PrcView
Norman 6.00.02 2009.02.09 -
nProtect 2009.1.8.0 2009.02.09 -
Panda 9.5.1.2 2009.02.09 -
PCTools 4.4.2.0 2009.02.09 -
Prevx1 V2 2009.02.09 -
Rising 21.15.50.00 2009.02.07 -
SecureWeb-Gateway 6.7.6 2009.02.09 -
Sophos 4.38.0 2009.02.09 -
Sunbelt 3.2.1847.2 2009.02.07 -
Symantec 10 2009.02.09 -
TheHacker 6.3.1.5.250 2009.02.09 Aplicacion/Processor.20
TrendMicro 8.700.0.1004 2009.02.09 PAK_Generic.001
VBA32 3.12.8.12 2009.02.08 -
ViRobot 2009.2.9.1596 2009.02.09 -
VirusBuster 4.5.11.0 2009.02.09 -
Also! I my world this Script sounds to good to be true!
I just made a quick check what is does. And according to the content in this Scripts .reg file and .bat file it is really doing a lot of strange thing!
Perhaps I am way out here so please correct if I am totally wrong.
But. Perhaps a word of warning is in place here!
|