Should I block it?
Yes, 98% block recommendation.
Possible reason:
Multiple malware detections
Additional versions
tnodup.exe
TNod User & Password Finder by Tukero[X]Team
| Version: | 1, 4, 2, 3 |
| MD5: | 18947d264d3e605199f07cae18c1d8e6 |
| SHA1: | cce10ca3fd0349441fe83ec58f51eccc9c460b91 |
| SHA256: | 7ebfbda5059c85da34a32401e9e994c9460362f228d842f1d89a9479c9d9830a |
Warning 33 antivirus scanners has detected malware.
Overview
tnodup.exe is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). It is installed with a couple of know programs including TNod User & Password Finder published by Tukero[X]Team and TNod User & Password Finder published by Tukero[X]Team.
Details
| File name: | tnodup.exe |
| Publisher: | Tukero[X]Team |
| Product name: | TNod User & Password Finder |
| Typical file path: | C:\Program Files\tnod user & password finder\tnodup.exe |
| File version: | 1, 4, 2, 3 |
| Size: | 1000.73 KB (1,024,748 bytes) |
| Build date: | 7/1/2013 10:26 AM |
| Digital DNA |
| File packed: | No |
| .NET CLR: | No |
More details
Programs
The following programs will install this file
“TNod User & Password Finder is software that is used to search the internet for activation keys for any version of NOD32 programs. In particular, it provides the username and password for ESET NOD32 Smart Security and ESET NOD32 Antivirus. ESET NOD32 Antivirus and Smart Security are programs that provide protection from malicious programs such as viruses, spyware, and malware. These anti-virus protection programs require a license code ...”
Behaviors
Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'TNOD UP' → "C:\Program Files\TNod User & Password Finder\TNODUP.exe" /i
Malware detections
Based on 40+ industry antivirus scanners, 33 of them detected the following malware.
| Antivirus engine | Engine version | Detection |
| Agnitum |
5.5.1.3 |
RiskWare.HackAV!P9GykJz2NdU |
| AhnLab V3 Internet Security |
2013.11.25 |
Trojan/Win32.Gen |
| Avira AntiVir |
7.11.115.108 |
TR/Zusy.11827.3 |
| avast! |
8.0.1489.320 |
Win32:Malware-gen |
| AVG |
13.0.0.3169 |
Fat-Obfuscated |
| Baidu Antivirus |
3.5.1.41473 |
Malware.Win32.RiskTool.40 |
| BitDefender |
7.2.5028.0 |
Gen:Variant.Zusy.11827 |
| Bkav Security |
1.3.0.4562 |
W32.Cloddf5.Trojan.0b16 |
| CAT Quick Heal |
11.13.12.00 |
(Suspicious) - DNAScan |
| Clam AntiVirus |
0.97.3.0 |
Win.Trojan.Zusy-91 |
| Commtouch |
5.4.1.7 |
W32/Trojan.TYNO-1842 |
| Comodo Internet Security |
17329 |
UnclassifiedMalware |
| Dr.Web |
8.13.11.25 |
Trojan.Click2.49081 |
| Emsisoft Anti-Malware |
3.0.0.589 |
Gen:Variant.Zusy.11827 (B) |
| ESET NOD32 |
7.9089 |
a variant of Win32/RiskWare.HackAV.JA |
| Fortinet |
5.1.147.0 |
W32/RiskWare_HackAV.JA |
| G Data |
13.11.22 |
Gen:Variant.Zusy.11827 |
| Ikarus |
T3.1.5.6.0 |
Virus.Fat.Obfuscated |
| K7 AntiVirus |
9.174.10294 |
Trojan ( 001e15121 ) |
| K7GW |
9.174.10294 |
Trojan ( 001e15121 ) |
| Kingsoft |
2013.4.9.267 |
Win32.Troj.Generic.a.(kcloud) |
| Malwarebytes |
1.75.0.1 |
Trojan.Agent.CK |
| McAfee |
5.600.1067 |
RDN/Generic PUP.x!bmh |
| McAfee Gateway Anti-Malware |
v2013-dat |
Heuristic.LooksLike.Win32.Suspicious.F!83 |
| eScan by MicroWorld |
12.0.250.0 |
Gen:Variant.Zusy.11827 |
| NANO AntiVirus |
0.28.0.56316 |
Trojan.Win32.Click2.bwoqvx |
| Norman |
7.02.06 |
Redosdru.LS |
| Panda Antivirus |
10.0.3.5 |
Trj/CI.A |
| Sophos |
4.95.0 |
Mal/Generic-S |
| Symantec |
20131.1.5.61 |
Trojan.Gen |
| Trend Micro |
9.740.0.1012 |
TROJ_SPNR.29GI13 |
| Trend Micro HouseCall |
9.700.0.1001 |
TROJ_SPNR.29GI13 |
| VIPRE Antivirus |
23684 |
Trojan-Dropper.Win32.Resdro.b (v) (not malicious) |
Distribution by Windows OS
| OS version | distribution |
| Windows 7 Ultimate |
100.00% |
|
Distribution by country
Greece installs about 50.00% of TNod User & Password Finder.
Distribution by PC manufacturer
| PC Manufacturer | distribution |
| Lenovo |
100.00% |
|