Home Malware Programs Trojans Trojan.FraudPack

Trojan.FraudPack

Posted: February 29, 2008

Threat Metric

Threat Level: 9/10
Infected PCs: 1,698
First Seen: July 24, 2009
Last Seen: January 23, 2022
OS(es) Affected: Windows

Trojan.FraudPack is a Trojan that delivers rogue security applications onto your PC. Like many Trojans, Trojan.FraudPack has been observed to use browser exploits and malicious advertising scripts to infect new computers without consent. Rogue security programs distributed by Trojan.FraudPack are known to cause many different problems such as preventing applications from running, hijacking web browsers to redirect you to dangerous websites, creating fake infection alerts and corrupting the Windows Registry. Removing Trojan.FraudPack should be a natural part of an overall system scan that removes Trojan.FraudPack's rogue security programs from your computer, since removing the threat while leaving Trojan.FraudPack intact will not solve the root of your problems.

Trojan.FraudPack is Just a Chauffeur for Fake Security Software

Trojan.FraudPack is the seedy side of rogue security anti-virus programs that the criminals don't want you to know about – although the rogue security programs delivered by Trojan.FraudPack are all obnoxiously visible, Trojan.FraudPack itself is well-hidden, being a clear sign of hostile intent that ruins the atmosphere of the scam. Trojan.FraudPack is known to distribute rogue security applications like Antivirus Monitor, Antivirus Soft, Antimalware GO, Antivirus .NET, AntiVira AV and many more.

Trojan.FraudPack will try to infect your computer through hostile scripts that are hosted on dangerous websites or embedded in dangerous advertisements. Disabling Flash and JavaScript will help you reduce the vectors for Trojan.FraudPack infections, but even these actions can't keep your computer completely safe. Interacting with the websites or advertisements in question isn't always necessary; sometimes, all that's needed is for the website or advertisement to load.

The main purpose of a Trojan.FraudPack infection is to download and install (or 'drop') one of the above rogue security programs on your PC, sometimes through the use of fake errors imitating Windows alerts. After this, the rogue security program takes up most of the limelight, creating countless fake infection alerts and other system problems. Although the threat will persistently try to get you to spend money on an activation key, following along with Trojan.FraudPack's plan will only harm your computer and your finances.

Clearing Out the Pack of Frauds

You may experience other problems while Trojan.FraudPack and Trojan.FraudPack's rogue security applications are on your PC. The most common symptoms include:

  • Fake security program infections that result in the program crashing when you try to launch it. Rogue security applications will do this to avoid any possibility of real anti-malware software detecting them. One possible error that's used by Trojan.FraudPack-related infections contains the following text:

    "Application cannot be executed. The file [executable file] is infected. Do you want to activate your anti-virus software now?"

  • Browser hijacks that control your browsing habits. You may see an error that stops you from visiting a website related to PC security, or you may be redirected to the rogue security product's homepage.

Deleting Trojan.FraudPack along with any other malware Trojan.FraudPack dropped on your PC should be considered absolutely required for insuring your computer's privacy. Attempting to find and remove Trojan.FraudPack yourself is a difficult task that is best reserved for situations where all other solutions have failed.

Rather than taking the hard option, go easy on yourself and use an actual anti-malware program to hunt down and take out Trojan.FraudPack for you. Switching to Safe Mode may be necessary to stop Trojan.FraudPack from avoiding its imminent destruction.

Aliases

Trojan.FraudPack [Ikarus]PUP/Win32.Helper [AhnLab-V3]TR/FraudPack.R.7 [AntiVir]Win32:PUP-gen [PUP] [Avast]Artemis!BF6D991EA7F0 [McAfee]Generic19.MSP [AVG]W32/FraudPack.BJVJ!tr [Fortinet]VirTool.Win32.Obfuscator.ah!k (v) [Sunbelt]Win-Trojan/Fraudpack.245760.L [AhnLab-V3]TR/FraudPack.bjvj [AntiVir]Trojan.Fakealert.18898 [DrWeb]Mal/FakeAV-DO [Sophos]Trojan.Generic.KDV.36266 [BitDefender]Trojan.Win32.FraudPack.bjvj [Kaspersky]Trojan.Fraudpack-4748 [ClamAV]
More aliases (714)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%LOCALAPPDATA%\asam.exe File name: asam.exe
Size: 61.18 KB (61184 bytes)
MD5: 25ecbaf37ead446a21c6211f91202d6c
Detection count: 239
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: September 28, 2010
%USERPROFILE%\Start Menu\Programs\Startup\svchost.exe File name: svchost.exe
Size: 40.44 KB (40448 bytes)
MD5: 17ff88f8799d0af3f2128ec88b39ba5f
Detection count: 171
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: September 23, 2010
%TEMP%\yxxa.exe File name: yxxa.exe
Size: 40.96 KB (40960 bytes)
MD5: 299e2c761ef22b6871cf4e3311ec12c1
Detection count: 133
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: October 25, 2010
win32extension.dll File name: win32extension.dll
Size: 634.36 KB (634368 bytes)
MD5: 36a3b3793515056bfb9f0a6d42463b0e
Detection count: 61
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: March 4, 2010
win32extension.dll File name: win32extension.dll
Size: 643.07 KB (643072 bytes)
MD5: 272178fd5cd395c69f37efd8e70633f8
Detection count: 60
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: March 4, 2010
UpdateCheck.dll File name: UpdateCheck.dll
Size: 647.16 KB (647168 bytes)
MD5: 7b98a061442e618e8d1f8e97bc947baf
Detection count: 55
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: March 4, 2010
UpdateCheck.dll File name: UpdateCheck.dll
Size: 645.12 KB (645120 bytes)
MD5: 76e28c8856b78228dd41ab3c9c313699
Detection count: 54
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: March 4, 2010
UpdateCheck.dll File name: UpdateCheck.dll
Size: 619.52 KB (619520 bytes)
MD5: 5e61c8e678d821b5ac9ca80dbb0a781b
Detection count: 54
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: April 3, 2010
UpdateCheck.dll File name: UpdateCheck.dll
Size: 647.16 KB (647168 bytes)
MD5: d5c8d529152f31397b1761d6925a123e
Detection count: 53
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: March 4, 2010
win32extension.dll File name: win32extension.dll
Size: 378.36 KB (378368 bytes)
MD5: 34d13d479446dcf6fa828b252312d278
Detection count: 53
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: April 3, 2010
%LOCALAPPDATA%\tnmmokolq\tsvswvcuqiw.exe File name: tsvswvcuqiw.exe
Size: 245.24 KB (245248 bytes)
MD5: e6bcc2e1376b7b97d5ee63989c6a6996
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\tnmmokolq
Group: Malware file
Last Updated: November 12, 2010
%USERPROFILE%\Local Settings\Application Data\Microsoft\PinGuide\PinGuideUDF.exe File name: PinGuideUDF.exe
Size: 379.9 KB (379904 bytes)
MD5: bf6d991ea7f0d4471173d3a3003f3bd0
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data\Microsoft\PinGuide
Group: Malware file
Last Updated: June 15, 2012
%PROGRAMFILES%\svchost.exe File name: svchost.exe
Size: 27.64 KB (27648 bytes)
MD5: e5378ab9a869d4b602e5570deb4d0f6f
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%
Group: Malware file
Last Updated: November 2, 2010
asam.exe File name: asam.exe
Size: 99.58 KB (99584 bytes)
MD5: 404e83c64f63abc1e089606610c82087
Detection count: 22
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: June 29, 2010
%WINDIR%\PRAGMAfpcioufnlq\PRAGMAd.sys File name: PRAGMAd.sys
Size: 52.22 KB (52224 bytes)
MD5: f775d72d8b8a217c890cf7d7fa20d087
Detection count: 16
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\PRAGMAfpcioufnlq
Group: Malware file
Last Updated: November 2, 2010
%LOCALAPPDATA%\gpmtwjyre\rinhhgkuqiw.exe File name: rinhhgkuqiw.exe
Size: 245.76 KB (245760 bytes)
MD5: 502ed77e17e0a1f4ef6f2cfe3c208c85
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\gpmtwjyre
Group: Malware file
Last Updated: November 12, 2010
%LOCALAPPDATA%\xmtdyy\ngtcwo.exe File name: ngtcwo.exe
Size: 343.29 KB (343296 bytes)
MD5: 57d17b820453114f47081e2ef1def4e4
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\xmtdyy
Group: Malware file
Last Updated: November 2, 2010
UpdateCheck.dll File name: UpdateCheck.dll
Size: 329.72 KB (329728 bytes)
MD5: c93418bfcf557bf606ae97ab87c49b7f
Detection count: 6
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: March 9, 2010
UpdateCheck.dll File name: UpdateCheck.dll
Size: 313.34 KB (313344 bytes)
MD5: 5a9a9623416e984188c6b6b2e9aaf362
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: March 9, 2010
UpdateCheck.dll File name: UpdateCheck.dll
Size: 329.72 KB (329728 bytes)
MD5: b81a80abae5bb92fb4cd79eebe230f54
Detection count: 4
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: March 9, 2010

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}

Related Posts

Loading...