Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Trojan.FakeAV.WIS (Windows Internet Scanner)

 

 

Name:

Trojan.FakeAV.wis

Descr. Added:

July 10, 2012

Type:

Trojan

Risk:

Low

Payload:

N/A

At risk systems:

Windows 95/98/ME/XP/NT/2003

 

 

Malware problems?   We can help.  Free Removal Tools.

 

 

Description:

 

When Trojan.FakeAV.wis is executed, it performs the following activities:

Liek other forms of Scareware it displays false reports of threats on the computer. The user is then prompted to pay for a full license of the application in order to remove the fake threats, as shown below:

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

It drops the following files on the system:

%Appdata%\Protector-cnfk.exe
%Windir%\Temp\cteng_11_1_<RandomCharacter>.dat
%Windir%\Temp\cteng_11_1_<RandomCharacter>.dat
%Windir%\Temp\cteng_11_1_<RandomCharacter>.dat
%Windir%\Temp\cteng_11_1_<RandomCharacter>.dat
%Windir%\Temp\cteng_11_1_<RandomCharacter>.dat

It creates/modifies the following registry entries:

Debugger = %Appdata%\Protector-cnfk.exe reg"
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe

Debugger = %Appdata%\Protector-cnfk.exe task"
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe

 

 

 

 

 

 

 
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 - Industry Leading Endpoint Security Solution

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4