Emsisoft Malware-Info
Name: Adware.Win32.ICQ Sniff
Risklevel: Elevated Risk
Company: Ufasoft Inc - http://www.ufasoft.com/
Description:
Ufasoft Inc provides us with keylogger ICQ Sniff which is a program that intercepts messages and user details, including passwords, across the whole LAN in real time. It is possible to receive and view all these messages to and from all LAN users in the same time they will receive or send it. All intercepted messages are also stored in files, which can be later processed and analyzed.
Removal instructions for Adware ICQ Sniff:
To delete this malware infection, buy Emsisoft Anti-Malware.
Guaranteed removal of Adware ICQ Sniff.
Run a full scan on all drives and move all detected items to the quarantine.
More details about this danger:
Characteristics:
- Includes ARP-spoofer, allowing capturing behind switch-hubs.
- Intercepts messages and user details.
- Intercepted messages can be stored in files.
- Possible to receive and view all these messages to and from all LAN users in the same time.
- It is free to download.
Installation: Installed through EXE
Process: icqsnif.exe
Screenshots:
Used folders:
- C:\Program Files\Ufasoft\Sniffer
- C:\Program Files\Ufasoft\Sniffer\LNG
- C:\Program Files\Ufasoft\Sniffer\src
- C:\Program Files\Ufasoft\Sniffer\src\rpcapd
- C:\Documents and Settings\Sapna\Start Menu\Programs\Ufasoft Snif
Used files:
- C:\Program Files\Ufasoft\Sniffer\homepage.url
[56 Bytes] Internet Shortcut - C:\Program Files\Ufasoft\Sniffer\icqdump.exe
[10240 Bytes] Application - C:\Program Files\Ufasoft\Sniffer\icqsnif.exe
[57856 Bytes] Application - C:\Program Files\Ufasoft\Sniffer\iwconfig.exe
[7680 Bytes] Application - C:\Program Files\Ufasoft\Sniffer\iwlist.exe
[7168 Bytes] Application - C:\Program Files\Ufasoft\Sniffer\license.txt
[2651 Bytes] Text Document - C:\Program Files\Ufasoft\Sniffer\pthreadVC.dll
[53299 Bytes] Application Extension - C:\Program Files\Ufasoft\Sniffer\rpcapd.exe
[40960 Bytes] Application - C:\Program Files\Ufasoft\Sniffer\setup.exe
[44032 Bytes] Application - C:\Program Files\Ufasoft\Sniffer\setup.inf
[2118 Bytes] Setup Information - C:\Program Files\Ufasoft\Sniffer\snif.bls
[2526503 Bytes] BLS File - C:\Program Files\Ufasoft\Sniffer\snif.chm
[111736 Bytes] Compiled HTML Help file - C:\Program Files\Ufasoft\Sniffer\snif_ru.chm
[83396 Bytes] Compiled HTML Help file - C:\Program Files\Ufasoft\Sniffer\snifmon.exe
[98304 Bytes] Application - C:\Program Files\Ufasoft\Sniffer\tcpdump.exe
[15360 Bytes] Application - C:\Program Files\Ufasoft\Sniffer\tcpflow.exe
[11264 Bytes] Application - C:\Program Files\Ufasoft\Sniffer\tcpslice.exe
[11264 Bytes] Application - C:\Program Files\Ufasoft\Sniffer\tcpstat.exe
[12800 Bytes] Application - C:\Program Files\Ufasoft\Sniffer\upgrade4.dat
[4398 Bytes] DAT File - C:\Program Files\Ufasoft\Sniffer\usft_sn4.sys
[15760 Bytes] System file - C:\Program Files\Ufasoft\Sniffer\usft_wifi.sys
[230032 Bytes] System file - C:\Program Files\Ufasoft\Sniffer\LNG\cn.lng
[397 Bytes] LNG File - C:\Program Files\Ufasoft\Sniffer\LNG\de.lng
[217 Bytes] LNG File - C:\Program Files\Ufasoft\Sniffer\LNG\en.lng
[479 Bytes] LNG File - C:\Program Files\Ufasoft\Sniffer\LNG\ru.lng
[677 Bytes] LNG File - C:\Program Files\Ufasoft\Sniffer\src\pcap.h
[11144 Bytes] H File - C:\Program Files\Ufasoft\Sniffer\src\pcap-int.h
[12760 Bytes] H File - C:\Program Files\Ufasoft\Sniffer\src\pcap-new.c
[54364 Bytes] C File - C:\Program Files\Ufasoft\Sniffer\src\pcap-remote.c
[73902 Bytes] C File - C:\Program Files\Ufasoft\Sniffer\src\pcap-remote.h
[16759 Bytes] H File - C:\Program Files\Ufasoft\Sniffer\src\remote-ext.h
[13856 Bytes] H File - C:\Program Files\Ufasoft\Sniffer\src\sockutils.c
[42776 Bytes] C File - C:\Program Files\Ufasoft\Sniffer\src\sockutils.h
[7123 Bytes] H File - C:\Program Files\Ufasoft\Sniffer\src\rpcapd\daemon.c
[49260 Bytes] C File - C:\Program Files\Ufasoft\Sniffer\src\rpcapd\daemon.h
[2243 Bytes] H File - C:\Program Files\Ufasoft\Sniffer\src\rpcapd\fileconf.c
[6446 Bytes] C File - C:\Program Files\Ufasoft\Sniffer\src\rpcapd\fileconf.h
[1804 Bytes] H File - C:\Program Files\Ufasoft\Sniffer\src\rpcapd\Makefile
[1116 Bytes] File - C:\Program Files\Ufasoft\Sniffer\src\rpcapd\rpcapd.c
[22946 Bytes] C File - C:\Program Files\Ufasoft\Sniffer\src\rpcapd\rpcapd.h
[2307 Bytes] H File - C:\Program Files\Ufasoft\Sniffer\src\rpcapd\utils.c
[5250 Bytes] C File - C:\Program Files\Ufasoft\Sniffer\src\rpcapd\utils.h
[58 Bytes] H File - C:\Documents and Settings\Sapna\Desktop\Ufasoft IM Snif.lnk
[636 Bytes] Shortcut - C:\Documents and Settings\Sapna\Desktop\Ufasoft Snif.lnk
[630 Bytes] Shortcut - C:\Documents and Settings\Sapna\Start Menu\Programs\Ufasoft Snif\Homepage.lnk
[667 Bytes] Shortcut - C:\Documents and Settings\Sapna\Start Menu\Programs\Ufasoft Snif\Ufasoft IM Snif.lnk
[648 Bytes] Shortcut - C:\Documents and Settings\Sapna\Start Menu\Programs\Ufasoft Snif\Ufasoft Snif.lnk
[642 Bytes] Shortcut - C:\Program Files\Ufasoft\Sniffer\AdapterInfo.exe
[9216 Bytes] Application - C:\Program Files\Ufasoft\Sniffer\arpspoof.exe
[9728 Bytes] Application
Additional information might be found here:
Search
at Google for
Adware ICQ Sniff
Search at Bing for
Adware ICQ Sniff
Search
at Yahoo for
Adware ICQ Sniff
How can I protect myself from Adware ICQ Sniff?
Important!
You essentially need an antivirus product, that is not only able to clean infections, but also protect your PC permanently from new dangers.
This is the only way to prevent data loss and unnecessary hassle and costs of new installations of your operating system.
Take your chance and buy the multiple awarded protection software Emsisoft Anti-Malware today!
Only $40 for the security of your computer.
Buy Emsisoft Anti-Malware online:
Trust only on the best protection software!
Spring Offer!
Don't miss this: To your bought 1-year license of Emsisoft Anti-Malware or Emsisoft Internet Security Pack or higher you can now get
a free license of the CyberGhost Anonymizer for free.
Your advantage: Surf anonymously and visit websites that are restricted in your country.
Only a few days left! Order here
























