Home Malware Programs Trojans Trojan-Downloader.Win32.FraudLoad.has

Trojan-Downloader.Win32.FraudLoad.has

Posted: September 16, 2010

Trojan-Downloader.Win32.FraudLoad.has is a malicious Trojan which intentionally customizes your system settings and adds new values to the system registry. Trojan-Downloader.Win32.FraudLoad.has launches automatically as your system warms up and then produces warning alerts with real harm. Trojan-Downloader.Win32.FraudLoad.has uses the alerts to scare users but sooner or later some crucial system depreciation will result. Use a proven malware remover to terminate Trojan-Downloader.Win32.FraudLoad.has immediately.

Aliases

Trojan.Win32.FraudPack.bkhe (Kaspersky Lab)
FakeAlert-OZ (McAfee)
Mal/FakeAV-EM (Sophos)
Trojan:Win32/Tibs.JL (Microsoft)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\dfrgsnapnt.exe
    2 %Temp%\eapp32hst.dll
    3 %Temp%\topwesitjh
    4 %Temp%\wscsvc32.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System][HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]HKEY..\..\..\..{RegistryKeys}[HKEY_CURRENT_USER\Software]
Loading...