Home / malware TrojanDownloader:Win32/Anmoea.A
First posted on 05 June 2014.
Source: MicrosoftAliases :
There are no other names known for TrojanDownloader:Win32/Anmoea.A.
Explanation :
Threat behavior
This threat contacts a remote host at uravidata.com using port 80. It then downloads and runs setupviewtmp.exe.
It can also detect and uninstall security products from the following vendors:
- AhnLab
- ESET
- ESTsoft
- NaverVaccine
- Trend Micro
Analysis by Jody Koo
Symptoms
System changes
The following could indicate that you have this threat on your PC:
- You have these files:
setupviewtmp.exeLast update 05 June 2014