Home Malware Programs Rootkits Mal/FakeVirPk-B

Mal/FakeVirPk-B

Posted: January 5, 2010

Threat Metric

Threat Level: 9/10
Infected PCs: 5,225
First Seen: July 24, 2009
Last Seen: November 27, 2024
OS(es) Affected: Windows

Mal/FakeVirPk-B (or Trojan.SuspectCRC) is a sneaky computer threat that hides itself in the registry files of a compromised computer. Mal/FakeVirPk-B modifies computer settings, making it vulnerable to attackers and giving them access to sensitive information. Mal/FakeVirPk-B can also connect to a remote SMTP server and produces outbound traffic by sending out emails via the Internet. To prevent possible identity theft, remove Mal/FakeVirPk-B immediately.

Aliases

Hoax/Win32.Agent.gen [Antiy-AVL]TR/Agent.amy.1 [AntiVir]Hoax.Win32.Agent.amy [Kaspersky]Artemis!7B948792C642 [McAfee]WinFixer.IV [AVG]not-a-virus [Ikarus]FraudTool/Win32.BestSeller.gen [Antiy-AVL]APPL/WinFixer.46592 [AntiVir]Application.Win32.Adware.AVSystemCare [Comodo]Application.Winfixer.BD [BitDefender]not-a-virus:FraudTool.Win32.BestSeller.a [Kaspersky]FraudTool.Win32.Best [eSafe]W32/KillAV.I.gen!Eldorado [F-Prot]Adware [K7AntiVirus]FraudTool.BestSeller.a (Not a Virus) [CAT-QuickHeal]
More aliases (5501)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\8FE7EAC9DBF7DFD14D16A6C7CC7E4D34\gotnewupdate.exe File name: gotnewupdate.exe
Size: 745.47 KB (745472 bytes)
MD5: 09add4d89b20e1266c00d2e764ff9644
Detection count: 482
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\8FE7EAC9DBF7DFD14D16A6C7CC7E4D34
Group: Malware file
Last Updated: May 4, 2010
%WINDIR%\system32\winlogon32.exe File name: winlogon32.exe
Size: 44.54 KB (44544 bytes)
MD5: db41868587c95a01aaa2f1b254f37c88
Detection count: 354
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: May 7, 2010
winlogon86.exe File name: winlogon86.exe
Size: 27.13 KB (27136 bytes)
MD5: e0ab935bf471e7cf51d2163ce6daa842
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
winhelper86.dll File name: winhelper86.dll
Size: 21.5 KB (21504 bytes)
MD5: 9d85a41e05681133f7e5e7c461c289b5
Detection count: 76
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: April 15, 2010
setup.exe File name: setup.exe
Size: 145.4 KB (145408 bytes)
MD5: be7a3a0203947d2d4e48835d6ea76327
Detection count: 72
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 20, 2010
svchost.exe File name: svchost.exe
Size: 36.35 KB (36356 bytes)
MD5: fe403a64c7a0dc2135de8b7ea12c5235
Detection count: 71
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 20, 2010
svchost32.exe File name: svchost32.exe
Size: 81.92 KB (81920 bytes)
MD5: e100dc56587c4b7261c1343a56d7423c
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 20, 2010
%TEMP%\Hk1.exe File name: Hk1.exe
Size: 145.4 KB (145408 bytes)
MD5: 03cd94952410f824f7329050cf9ad29e
Detection count: 65
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: December 7, 2010
xxx8227.exe File name: xxx8227.exe
Size: 89.6 KB (89604 bytes)
MD5: 4c0da52093b68ad1effe8199587b42c9
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 23, 2010
win32extension.dll File name: win32extension.dll
Size: 372.73 KB (372736 bytes)
MD5: a0b7593f2aaba86ac2b9e0777be9c57f
Detection count: 60
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: March 23, 2010
C:\9iakp4.exe File name: 9iakp4.exe
Size: 24.06 KB (24064 bytes)
MD5: e1a987131602909b6eb11889cba5633b
Detection count: 53
File type: Executable File
Mime Type: unknown/exe
Path: C:\9iakp4.exe
Group: Malware file
Last Updated: December 19, 2021
helpers32.dll File name: helpers32.dll
Size: 27.64 KB (27648 bytes)
MD5: a0b5ab35d0f89bd0007a00585da0447f
Detection count: 36
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: April 15, 2010
smss32.exe File name: smss32.exe
Size: 37.88 KB (37888 bytes)
MD5: e8a1cee6410615c7536599962f6a06f0
Detection count: 32
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 7, 2010
wayebomi.exe File name: wayebomi.exe
Size: 51.72 KB (51720 bytes)
MD5: 20690f9ccb0e0e2d780561ab1143c090
Detection count: 31
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
msxml71.dll File name: msxml71.dll
Size: 230.4 KB (230404 bytes)
MD5: b1f33ca34b41c830e14fe84b01228a5f
Detection count: 26
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: April 1, 2010
helper32.dll File name: helper32.dll
Size: 25.6 KB (25600 bytes)
MD5: c9b23d86f912f7709dcea1dcd1814813
Detection count: 25
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: April 15, 2010
%APPDATA%\drivers\winupgro.exe File name: winupgro.exe
Size: 1.06 MB (1061376 bytes)
MD5: d84367293f7e7c61eea347b767f91a38
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\drivers
Group: Malware file
Last Updated: November 30, 2010
%USERPROFILE%\Desktop\setup_de.exe File name: setup_de.exe
Size: 262.16 KB (262160 bytes)
MD5: dba6689c1423c4387449c2ac6686c8e4
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Desktop
Group: Malware file
Last Updated: October 3, 2011
dgrpsetu32.dll File name: dgrpsetu32.dll
Size: 120.32 KB (120320 bytes)
MD5: 50dec1ee3040fb8118fae67e2af56ab7
Detection count: 15
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: April 8, 2010
%APPDATA%\winantiviruspro2006freeinstall_nl[1].exe File name: winantiviruspro2006freeinstall_nl[1].exe
Size: 92.88 KB (92880 bytes)
MD5: b56edb2b32396c4e44222f12fc630d83
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: November 1, 2011
%APPDATA%\newsoftwareinstaller[1].exe File name: newsoftwareinstaller[1].exe
Size: 144.15 KB (144152 bytes)
MD5: 6b45cbb5ff302933b36aaadfe2fbff42
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: September 21, 2011

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{376892AE-1825-4E5F-9F85-23F9640051CC}{94204837-0871-4E6A-A426-7F75B1B731F0}File name without pathmsa.exesmss32.exeHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Toolbar\{12A25CE9-0A93-4074-9516-A5B1A83141C9}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{FCCD9F7B-5BF3-4DC4-B131-CE069F8A62AB}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{FF20AF38-AD56-4361-AE03-339130767E26}

Additional Information

The following URL's were detected:
cubeexe.comsecurityonlinecomputer.net
Loading...