Should I block it?
Yes, 98% block recommendation.
Possible reason:
Multiple malware detections
Additional versions
tnodup.exe
TNod User & Password Finder by Tukero[X]Team
| Version: | 1, 4, 1, 0 |
| MD5: | 0ea8529b45b2d02bfe8ddef94abc283e |
| SHA1: | 93797738f6eb18b8da79957077292bde6a51e1a5 |
| SHA256: | a1e18bc272e7d5618496a6d32ad6b1fbea550ec76cf112b5ac1499c0366f6fdd |
Warning 28 antivirus scanners has detected malware.
Overview
tnodup.exe is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). This is typically installed with the program TNod User & Password Finder published by Tukero[X]Team and is most likely removed by most users once installed (67% removed).
Details
| File name: | tnodup.exe |
| Publisher: | Tukero[X]Team |
| Product name: | TNod User & Password Finder |
| Typical file path: | C:\Program Files\tnod user & password finder\tnodup.exe |
| File version: | 1, 4, 1, 0 |
| Size: | 1.8 MB (1,892,352 bytes) |
| Digital DNA |
| File packed: | No |
| .NET CLR: | No |
More details
Programs
The following program will install this file
“TNod User & Password Finder is software that is used to search the internet for activation keys for any version of NOD32 programs. In particular, it provides the username and password for ESET NOD32 Smart Security and ESET NOD32 Antivirus. ESET NOD32 Antivirus and Smart Security are programs that provide protection from malicious programs such as viruses, spyware, and malware. These anti-virus protection programs require a license code ...”
Behaviors
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'TNOD UP' → "C:\Program Files\TNod User & Password Finder\TNODUP.exe" /i
Malware detections
Based on 40+ industry antivirus scanners, 28 of them detected the following malware.
| Antivirus engine | Engine version | Detection |
| Ad-Aware |
12.0.163.0 |
Application.Generic.393045 |
| Agnitum |
5.5.1.3 |
Riskware.RiskWare!pZhVeGEIg6A |
| Antiy Labs AVL |
2.0.3.7 |
PSWTool/Win32.TNod.gen |
| avast! |
8.0.1489.320 |
Win32:PUP-gen [PUP] |
| AVG |
13.0.0.3169 |
PSW.Generic9.BCNS |
| Baidu Antivirus |
3.5.1.41473 |
Malware.Win32.Agent.40 |
| BitDefender |
7.2.5028.0 |
Application.Generic.393045 |
| Clam AntiVirus |
0.97.3.0 |
Win.Trojan.393045 |
| Comodo Internet Security |
17602 |
UnclassifiedMalware |
| Emsisoft Anti-Malware |
3.0.0.583 |
Application.Generic.393045 (B) |
| ESET NOD32 |
7.9282 |
Win32/RiskWare.HackAV.DM |
| F-Secure |
11.0.19100.45 |
Application.Generic.393045 |
| G Data |
13.8.22 |
Application.Generic.393045 |
| Ikarus |
T3.1.5.6.0 |
not-a-virus:AdWare.Win32.AdMedia |
| Jiangmin |
16.0.100 |
PSWTool.TNod.a |
| K7 AntiVirus |
9.175.10814 |
Riskware ( 0040f01a1 ) |
| K7GW |
12.7.0.12 |
Riskware |
| Kaspersky |
12.0.0.1221 |
not-a-virus:PSWTool.Win32.TNod.b |
| Kingsoft |
2013.4.9.267 |
Win32.Malware.Heur_Generic.A.(kcloud) |
| Malwarebytes |
1.75.0.1 |
Trojan.Agent.CK |
| McAfee |
5.600.1067 |
Artemis!0EA8529B45B2 |
| McAfee Gateway Anti-Malware |
v2013-dat |
Artemis!0EA8529B45B2 |
| eScan by MicroWorld |
12.0.250.0 |
Application.Generic.393045 |
| Norman |
7.03.02 |
keygen.P |
| Rising Antivirus |
25.0.0.11 |
PE:Trojan.Win32.Generic.12DC38EF!316422383 |
| Sophos |
4.96.0 |
Troj/KeyGen-HQ |
| Symantec |
20131.1.5.61 |
WS.Reputation.1 |
| VIPRE Antivirus |
25384 |
Trojan.Win32.Generic!BT |
Distribution by Windows OS
| OS version | distribution |
| Windows 7 Ultimate |
100.00% |
|
Distribution by country
Greece installs about 50.00% of TNod User & Password Finder.
Distribution by PC manufacturer
| PC Manufacturer | distribution |
| Lenovo |
100.00% |
|