
> Virus & Spyware Info
Virus & Spyware Info
We provide the latest information on new viruses, spyware, and other malware.
| Name |
Adware/Rogueware.MediCom.A |
| Alias |
None |
| Current Spread Level |
 |
System Threat Level |
 |
| Network Proliferation |
 |
Potential Danger Level |
 |
| Active Platform |
Windows |
Form/Type |
Rogueware |
| Method of Spread |
Download |
| Main Symptoms |
Induced payment through false/exaggerated detections. |
| Created Files |
launcher.exe, medicom.exe, medicomblk.dll, medicomup.exe,searced.log, uninstall.exe |
| File Size |
524,288 Byte |
Activity Date |
0000-00-00 |
| Country of Origin |
Republic of Korea |
Detection Date |
0000-00-00 |
| Similar/Altered Viruses |
|
| Detectable Engine |
2009.11.11.01 |
Reparable Engine |
2009.11.11.01 |
|
| Description |
[Summary]
Adware/Rogueware.MediCom.A is downloaded and installed without the user's knowledge. A list is shown with false adware or spyware detections and payment is induced in order to repair the malware.
[Propagation]
Adware/Rogueware.MediCom.A is downloaded and installed through other malware.
[Symptoms]
1. Creates files in the following path.
- (Program Folder)\medicom\launcher.exe
- (Program Folder)\medicom\medicom.exe
- (Program Folder)\medicom\medicomblk.dll
- (Program Folder)\medicom\medicomfnc.dll
- (Program Folder)\medicom\medicomres.dll
- (Program Folder)\medicom\medicomup.exe
- (Program Folder)\medicom\searced.log
- (Program Folder)\medicom\uninstall.exe
2. The following registry key is created in order to run automatically upon Windows startup.
- HKEY_LOCAL_MACHINE\
SOFTWARE\
Microsoft\
Windows\
CurrentVersion\
Run
- Name: medicom
- Data: "(Program Folder)\medicom\launcher.exe (Program Folder)\medicom\medicomup.exe"
3. The registry created by Adware/Rogueware.MediCom.A is shown below.
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\medicom
- HKCU\Software\medicom
[Reference Information]
- In Windows, (Program Folder) generally refers to C:\Program Files |
| Manual Treatment Method |
[Repairing with nProtect Netizen / nProtect Personal]
1. Run the product and clik on the ON-SCAN button by the top.
2. Check on all the files in Settings and click on the Scan Now button.
3. If a malware is detected through the scan, click on the Yes button in the Treatment Option Window.
4. Check if the malware has been successfully repaired.
[Repairing with nProtect Anti-Virus/Spyware 2007 / nProtect GameGuard Personal 2007]
1. Run the product and update the engine and patch file to the latest version. (Using the main window, tray icon, or start menu)
2. Select the Virus/Spyware tab and click on the Scan Now button.
3. If a malware is detected through the scan, click on the Repair button.
4. Check if the malware has been successfully repaired. |
Contents Copyright Notice
The analyzed data above is copyright material by ISARC(INCA Internet Security Analysis & Response Center) and may not be used without permission.
Non-profit organizations or personal individuals may use the contents, but must cite the source, and any use of the information for commercial purposes or by corporations must first contact our contents manager and get our approval.
Information Contents Inquiries : sale@inca.co.kr
|