ViewPassword

ViewPassword

Known Toolbar

by Bechiro S.L.

What is ViewPassword?

ViewPassword is software application developed by Bechiro S.L.. It is most commonly found on computers running Windows 7 with nearly 52.66% of installations running this operating system. ViewPassword's installer is typically 1.00 MB in size and installs around 11 files.

ViewPassword is most popular in the United States with 41.67% of installations residing in this country.

ViewPassword adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About ViewPassword?

The software in question is distributed through a variety of download sites known for hosting malware. This toolbar/web browser extension, supported by advertisements and search features, is usually installed as an optional add-on alongside third-party software. Upon installation, the toolbar changes the home page and new tab pages to an affiliate search portal that generates shared search revenue using a primary search engine. It also modifies the default search provider.

Multiple virus scanners have detected malware in ViewPassword.

150.dll (MD5: 8c658e481497c3c91f6a250ff85873e8) has been flagged by 2 scanners:
Scanner Software Result
Dr.Web Trojan.Revizer.1
Symantec WS.Reputation.1
174.dll (MD5: db97437eed12d6108d0bf09af0e6b8db) has been flagged by 4 scanners:
Scanner Software Result
ESET-NOD32 a variant of Win32/AdWare.AddLyrics.BD
Symantec WS.Reputation.1
Trend Micro HKTL_PASSVIEW
TrendMicro-HouseCall HKTL_PASSVIEW
wdViewPasswordu.exe (MD5: 8e13548237066790afdddb1c63e2c98e) has been flagged by 21 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11442503
AVG Generic5.AYWT
Bitdefender Trojan.Generic.11442503
Comodo Security Application.Win32.Adware.WDUnlocker.A
Emsisoft Anti-Malware Trojan.Generic.11442503 (B)
ESET-NOD32 a variant of Win32/AdWare.AddLyrics.AT
F-Secure Trojan.Generic.11442503
G Data Trojan.Generic.11442503
MicroWorld-eScan Trojan.Generic.11442503
Qihoo-360 HEUR/Malware.QVM10.Gen
TrendMicro-HouseCall Suspicious_GEN.F47V0628
VIPRE Antivirus Trojan.Win32.Generic!BT
avast! Win32:Malware-gen
Kaspersky not-a-virus:HEUR:AdWare.Win32.Agent.heur
Symantec WS.Reputation.1
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent
Baidu-International Adware.Win32.Agent.ark
McAfee Artemis!F6804B775F74
McAfee-GW-Edition Artemis!F6804B775F74
Sophos Generic PUA AH
Trend Micro HKTL_PASSVIEW
ViewPasswordoo174.exe (MD5: f6804b775f74c1e248e569f49fd1acff) has been flagged by 13 scanners:
Scanner Software Result
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent
avast! Win32:Adware-BSL [PUP]
AVG Generic5.AXZZ
Baidu-International Adware.Win32.Agent.ark
ESET-NOD32 a variant of Win32/AdWare.AddLyrics.AQ
Kaspersky not-a-virus:HEUR:AdWare.Win32.Agent.heur
McAfee Artemis!F6804B775F74
McAfee-GW-Edition Artemis!F6804B775F74
Qihoo-360 Win32/Virus.Adware.5c6
Sophos Generic PUA AH
Symantec WS.Reputation.1
Trend Micro HKTL_PASSVIEW
TrendMicro-HouseCall HKTL_PASSVIEW
ViewPasswordFIXQNw.exe (MD5: 42048e4f82027f951741c1fac2239257) has been flagged by 22 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.147412
Antiy-AVL Trojan/Win32.SGeneric
AVG Generic5.AYWT
Baidu-International Adware.Win32.AddLyrics.BAT
Bitdefender Gen:Variant.Adware.Graftor.147412
Comodo Security Application.Win32.Adware.WDUnlocker.A
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.147412 (B)
ESET-NOD32 a variant of Win32/AdWare.AddLyrics.AT
F-Secure Gen:Variant.Adware.Graftor.147412
G Data Gen:Variant.Adware.Graftor.147412
IKARUS anti.virus PUA.AddLyrics
MicroWorld-eScan Gen:Variant.Adware.Graftor.147412
Qihoo-360 HEUR/Malware.QVM10.Gen
TrendMicro-HouseCall Suspicious_GEN.F47V0701
VIPRE Antivirus Trojan.Win32.Generic!BT
avast! Win32:Malware-gen
Kaspersky not-a-virus:HEUR:AdWare.Win32.Agent.heur
Symantec WS.Reputation.1
McAfee Artemis!F6804B775F74
McAfee-GW-Edition Artemis!F6804B775F74
Sophos Generic PUA AH
Trend Micro HKTL_PASSVIEW

Software Behaviors

Scheduled tasks:
  • ViewPassword.exe is scheduled as a task named 'ViewPassword Update' (runs daily at 5:21 PM).

Startup Entries

Startup tasks:
  • ViewPassword.exe is automatically launched at startup through a scheduled task named ViewPassword Update.

Software Details

URL:
Support:
Installation path:
C:\Program Files\viewpassword
Uninstaller:
C:\Program Files\ViewPassword\Uninstall.exe
Size:
1.00 MB
Language:
English

ViewPassword Executable Details

Primary executable:
ViewPassword.exe
Name:
ViewPassword
Path:
C:\Program Files\viewpassword\ViewPassword.exe
MD5:
1bb32094470e2889d48f0a6da7287de1
SHA-1:
SHA-256:
Files installed by ViewPassword
File Type Filename MD5
EXE
c6341412b0dfc7e36f6e7695a4973f86
DLL
150.dll
Malware
8c658e481497c3c91f6a250ff85873e8
DLL
174.dll
Malware
db97437eed12d6108d0bf09af0e6b8db
EXE
8e13548237066790afdddb1c63e2c98e
EXE
8dd88b24fb5fa54e1d8864078bba4455
EXE
f6804b775f74c1e248e569f49fd1acff
DLL
d4d27a177564239de96e6732b97688ec
EXE
42048e4f82027f951741c1fac2239257
EXE
43f3f6ef6e4327e8497122a44dcf78bc
XPI
54e30aa58039fd3bca5bd636c54f0989