Home > General > Pcciomon.exe


On port 10000 it opens an FTP server that provides full access to all files on all the physical and mapped drives of the infected computer. You may also refer to the Knowledge Base on the F-Secure Community site for further assistance. Go to View. Learn More About Company News Investors Careers Offices Labs Labs Labs blog Latest threats Remove threats Submit a sample Beta programs Support Support Knowledge base Software updates Community Support Tools Contact

This increments an infection counter on that webpage. Step Two: Select the associated program and then click Uninstall. The unpacked size of the worm is 61440 bytes. However, not everyone is an expert, even if he says so.

Step5: Click "File Repair" button to enter the file name in the text box, then click on the download button, copy the downloaded file to the program directory. Another copy of the worm is created with a random name and '.DLL' extension. More than 500.000 already infected! Removal Automatic action Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

Last user reviews for pcciomon.exe:0 reviews: - Be FIRST to add your review >> Share this page: Have you noticed that the longer you have your computer, the slower it runs? Propagation (E-mail) The worm collects e-mail addresses from files with following extensions: .HTM .DBX .EML .MSG .OFT .NWS .VCF .MBX .IMH .TXT .MSF The worm searches for files with these extensions Infection Counter Whenever the worm infects a computer it opens a web browser on a certain webpage. If the worm does not find any files in those folders, it copies itself to network shares with the following names: New WinZip File.exe Zipped Files.exe movies.exe The other network spreading

Download pcciomon.exe Repair Tool pcciomon.exe description and 100% Download free 1 file Home What is pcciomon.exe Error? The Trojan ends processes and services containing the following text: _AVP32 _AVP32.EXE _AVPCC _AVPCC _AVPCC.EXE _AVPM _AVPM.EXE AckWin32 AckWin32 ACKWIN32 AckWin32.exe AckWin32.exe ACKWIN32.EXE ADVXDWIN ADVXDWIN.EXE agentw.exe ALERTSVC ALERTSVC.EXE ALOGSERV alogserv ALOGSERV Step Two: Make sure to select the Show hidden files_new and folders options. Email propagation Dumaru.B uses its own SMTP engine to send emails with infected attachments.

However, many spyware/malware programs use filenames of usual, non-malware programs. Process library by alphabet: A B C D E F G H I J K L M N O P Q R S T U V W X Y Z 0 Once the program have been uninstall from Add or Remove Programs, you should also follow the steps to totally remove its associate files_new from the computer. Top most intriguing searches TaskManufacturerPercent Nwiz.exe?10 % HKCMD.EXEIntel8 % Unsecapp.exeMicrosoft7 % CCC.exeATI Technologies6 % Reader_SL.exeAdobe5 % ATI2evxx.exeATI Technologies4 % iTunesHelper.exeApple4 % S24EvMon.exeIntel4 % Cli.exeATI Technologies4 % WLLoginProxy.exeMicrosoft4 % ekrn.exeESET4 % SBAMSvc.exeSunbelt

The archive's name is LATEST.ZIP and it should be downloaded and put into the same folder where the F-Force utility is located. If that doesn't work, you will have to extract pcciomon.exe to your system directory. When 'filename.exe' is invoked the worm executes 'filename.exe:STR' instead. We were contacted by the organization that runs the site with that counter.

pcciomon.exeFix problems now! Please re-install a copy of the above file." "Windows\System32\pcciomon.exe missing or corrupt: Please re-install a copy of the above file." "Cannot find Windows\System32\pcciomon.exe" "Cannot find pcciomon.exe" pcciomon.exe is missing Unable to We recommend that you turn off the automatic startup of this program. The infected emails have the following structure: From: [[email protected]] or [[email protected]] To: [[email protected]] Subject: kepeslap erkezett!

E-mail addresses that have any of the following substrings are ignored by the worm: SYMANTEC MCAFEE VIRUS TREND PANDA SECUR SPAM NORTON ANTI CILLIN CA.COM KASPER TRUST AVG GROUPS.MSN NOMAIL.YAHOO.COM SCRIBE We recommend using the free antivirus software AVG Anti-Virus Free. How to fix pcciomon.exe errors If Windows notifies you of pcciomon.exe errors, the cause may be the result of damaged or corrupted registry entries. It's Free :) how are you?

Step Four: Click OK to confirm the modification. DeutschEnglish (US)EspañolFrançaisItalianoNederlandsPolskiPortuguês (Brasil)Русский中国日本한국의中國 Start to repair pcciomon.exe now! If this does not fix pcciomon.exe errors, we recommend uninstalling the program using the Control Panel and then running a scan of the Windows registry again.

The size of the main executable is about 95 kilobytes.

The DLL Escort is a DLL files fixer that allows its users to fix .dll errors, fix .exe errors, fix .sys files, repair corrupted files and download missing DLL files for If the file is located in another folder, you may have selected this path when installing the software. The F-Force utility needs the archive with the latest updates in order to function properly. Registry Modifications Creates these keys: [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "ScanRegistry" = "%System%\scanregw.exe /scan"[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState] "FullPath" = dword:00000001 [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "ShowSuperHidden" = dword:00000000 [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] "WebView" = dword:00000000 Detection F-Secure Anti-Virus detects this malware with the following updates:

Step Five: From Advanced options, locate and select Hidden files_new and folders. Step1: Download DLL Escort, install and run Step2: Click "Save File" and follow the on-screen instructions to install the program. May include code or other malware to damage both the system and the network. Terminating security software Dumaru enumerates the running processes and terminates the ones which have the following names: ZAUINST.EXE ZAPRO.EXE ZONEALARM.EXE ZATUTOR.EXE MINILOG.EXE VSMON.EXE LOCKDOWN.EXE ANTS.EXE FAST.EXE GUARD.EXE TC.EXE SPYXX.EXE PVIEW95.EXE REGEDIT.EXE

i send the details. Also the worm makes changes to the registry. Submit a sample to our Labs for analysis Submit Now Scan & clean your PC F-Secure Online Scanner will scan and clean your PC in just a few minutes for free Step Three: Make sure not to select the options for the Hide file extensions for known file types and Hide Protected Operating System files_new (Recommended)options.

Dear friend , use this Internet Explorer patch now! Latest DLL WargamingGameUpdater.exe freeBigupgrade.exe ASCPromote.exe AvCmUt3.exe CIRC.SignServer.exe enbhost.exe E_FPREG8C.EXE E_FBCSG8C.EXE E_FATIG8C.EXE Hao123Share.exe OReport3.exe OMailRpt.exe LCTC.exe IMTC.exe pcciomon.exe is considered to be trustworthy. If a matching folder is found, the worm opens it, enumerates files there, "borrows" one randomly selected file name and adds an EXE extension to it.

The tool can be downloaded from our web and ftp sites: The utility is distributed only in a ZIP archive that contains the following files: f-force.exe - the main The worm can modify Active Desktop files in order to launch another copy of itself named 'WinZip_Tmp.exe' using the ActiveX control. Share the knowledge on our free discussion forum. Step4: Click the "Fix DLL Errors" button to fix file error and speed up computer.

When the payload is activated, the worm enumerates all logical drives and damages files on them in a loop.