Home Malware Programs Trojans Trojan.Win32.FraudPack.zwr

Trojan.Win32.FraudPack.zwr

Posted: November 18, 2009

Trojan.Win32.FraudPack.zwr, or Mal/FakeAV-AD, is a malicious Trojan horse that may represent a security risk for the compromised PC system or its network environment. Trojan.Win32.FraudPack.zwr contains characteristics of a rogue antispyware application that uses aggressive and deceptive advertising along with false reports of exaggerated system security threats to persuade users to download and purchase their product. Trojan.Win32.FraudPack.zwr creates a startup registry entry which produces false security reports to scare the user into purchasing useless anti-spyware programs. Trojan.Win32.FraudPack.zwr shows all the signs of a high security risk and should be removed from the computer system immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %CommonAppData%\02142817\02142817.bat
    2 %CommonAppData%\02142817\02142817.exe
    3 %DesktopDir%\Security Tool.lnk
    4 %Programs%\Security Tool.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}[HKEY_CURRENT_USER\Control Panel\Desktop]
Loading...