Categories: Downloader
The downloader either launches the new malware or registers it to enable autorun
according to the local operating system requirements.
Visible Symptoms:
Files in system folders:
[%PROGRAM_FILES%]\webposition2\default-template200.htm
[%PROGRAM_FILES%]\webposition2\webpos20.ini
[%PROGRAM_FILES%]\webposition2\wpgold20.exe
[%PROGRAM_FILES%]\webposition2\wpsched20.exe
[%PROGRAM_FILES%]\webposition2\wpsched20.ini
[%PROGRAM_FILES%]\webposition2\default-template200.htm
[%PROGRAM_FILES%]\webposition2\webpos20.ini
[%PROGRAM_FILES%]\webposition2\wpgold20.exe
[%PROGRAM_FILES%]\webposition2\wpsched20.exe
[%PROGRAM_FILES%]\webposition2\wpsched20.ini
How to detect Web.Position:
Files:
[%PROGRAM_FILES%]\webposition2\default-template200.htm
[%PROGRAM_FILES%]\webposition2\webpos20.ini
[%PROGRAM_FILES%]\webposition2\wpgold20.exe
[%PROGRAM_FILES%]\webposition2\wpsched20.exe
[%PROGRAM_FILES%]\webposition2\wpsched20.ini
[%PROGRAM_FILES%]\webposition2\default-template200.htm
[%PROGRAM_FILES%]\webposition2\webpos20.ini
[%PROGRAM_FILES%]\webposition2\wpgold20.exe
[%PROGRAM_FILES%]\webposition2\wpsched20.exe
[%PROGRAM_FILES%]\webposition2\wpsched20.ini
Removing Web.Position:
You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.
Or buy it to remove ALL viruses from your computer.Also Be Aware of the Following Threats:
Removing Haxdoor.cu Backdoor
Polymorphic Downloader Removal instruction
Removing Pigeon.AVVA Trojan
Removing Arcvvir Trojan
No comments:
Post a Comment