Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

TROJAN.FAKEAV.XPHOME2012

 

 

Name:

Trojan.FakeAV.XPHome2012

Added:

December 15, 2011

Type:

Trojan

Risk:

Low

Payload:

N/A

At risk systems:

Windows 95/98/ME/XP/NT/2003

 

 

Malware problems?   We can help.  Free Removal Tools.

 

 

Description:

 

When Trojan.FakeAV.XPHome2012 is executed, it performs the following activities:

After execution, it drops the following file:

Appdata%\random3character.exe
(e.g. %Appdata%\ave.exe, %Appdata%\mtg.exe)

Upon execution of "%allusersprofile%\mtg.exe" it installs the fake antivirus "XP Home Security 2012" on the machine.

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

It also modifies the following registry entry:
HKEY_CLASSES_ROOT\exefile\shell\open\command]-

 

 

 

 

 

 

 
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 - Industry Leading Endpoint Security Solution

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4