Home Malware Programs Rootkits Trojan-Downloader.Win32.FraudLoad.gam

Trojan-Downloader.Win32.FraudLoad.gam

Posted: December 2, 2009

Threat Metric

Ranking: 10,345
Threat Level: 9/10
Infected PCs: 5,157
First Seen: July 24, 2009
Last Seen: September 6, 2023
OS(es) Affected: Windows

Trojan-Downloader.Win32.FraudLoad.gam is installed through a devious exploit and deceives the user by downloading other harmful malware onto the infected computer. Trojan-Downloader.Win32.FraudLoad.gam can download adware, spyware and other malware from various servers and sources on the Internet. Other symptoms include opening illicit network connections, self-mutation and the ability to disable weak software security. Risks which may prove detrimental to the computer user include the transmission of personal information without the user's consent. Trojan-Downloader.Win32.FraudLoad.gam can severely degrade the performance of your computer and poses a severe security risk. Terminate Trojan-Downloader.Win32.FraudLoad.gam upon detection.

Aliases

Hoax/Win32.Agent.gen [Antiy-AVL]TR/Agent.amy.1 [AntiVir]Hoax.Win32.Agent.amy [Kaspersky]Artemis!7B948792C642 [McAfee]WinFixer.IV [AVG]not-a-virus [Ikarus]FraudTool/Win32.BestSeller.gen [Antiy-AVL]APPL/WinFixer.46592 [AntiVir]Application.Win32.Adware.AVSystemCare [Comodo]Application.Winfixer.BD [BitDefender]not-a-virus:FraudTool.Win32.BestSeller.a [Kaspersky]FraudTool.Win32.Best [eSafe]W32/KillAV.I.gen!Eldorado [F-Prot]Adware [K7AntiVirus]FraudTool.BestSeller.a (Not a Virus) [CAT-QuickHeal]
More aliases (5501)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\8FE7EAC9DBF7DFD14D16A6C7CC7E4D34\gotnewupdate.exe File name: gotnewupdate.exe
Size: 745.47 KB (745472 bytes)
MD5: 09add4d89b20e1266c00d2e764ff9644
Detection count: 482
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\8FE7EAC9DBF7DFD14D16A6C7CC7E4D34
Group: Malware file
Last Updated: May 4, 2010
%WINDIR%\system32\winlogon32.exe File name: winlogon32.exe
Size: 37.88 KB (37888 bytes)
MD5: 4a0ab091489f7f9dcf298b2b9dd07582
Detection count: 389
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: May 4, 2010
%WINDIR%\system32\winlogon32.exe File name: winlogon32.exe
Size: 44.54 KB (44544 bytes)
MD5: db41868587c95a01aaa2f1b254f37c88
Detection count: 354
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: May 7, 2010
winupdate86.exe File name: winupdate86.exe
Size: 31.23 KB (31232 bytes)
MD5: 995945f39df67f488de242f9d4ad199c
Detection count: 86
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
winupdate86.exe File name: winupdate86.exe
Size: 31.23 KB (31232 bytes)
MD5: 8e36fdfa3a6fdc319d2fa8a5948fc481
Detection count: 85
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
winupdate86.exe File name: winupdate86.exe
Size: 35.32 KB (35328 bytes)
MD5: 5155c4617976cb5805343d57e7a2b797
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
setup.exe File name: setup.exe
Size: 145.4 KB (145408 bytes)
MD5: be7a3a0203947d2d4e48835d6ea76327
Detection count: 72
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 20, 2010
svchost.exe File name: svchost.exe
Size: 36.35 KB (36356 bytes)
MD5: fe403a64c7a0dc2135de8b7ea12c5235
Detection count: 71
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 20, 2010
svchost32.exe File name: svchost32.exe
Size: 81.92 KB (81920 bytes)
MD5: e100dc56587c4b7261c1343a56d7423c
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 20, 2010
%TEMP%\Hk1.exe File name: Hk1.exe
Size: 145.4 KB (145408 bytes)
MD5: 03cd94952410f824f7329050cf9ad29e
Detection count: 65
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: December 7, 2010
helpers32.dll File name: helpers32.dll
Size: 27.64 KB (27648 bytes)
MD5: a0b5ab35d0f89bd0007a00585da0447f
Detection count: 36
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: April 15, 2010
smss32.exe File name: smss32.exe
Size: 37.88 KB (37888 bytes)
MD5: e8a1cee6410615c7536599962f6a06f0
Detection count: 32
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 7, 2010
%APPDATA%\drivers\winupgro.exe File name: winupgro.exe
Size: 1.06 MB (1061376 bytes)
MD5: d84367293f7e7c61eea347b767f91a38
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\drivers
Group: Malware file
Last Updated: November 30, 2010
%USERPROFILE%\Desktop\setup_de.exe File name: setup_de.exe
Size: 262.16 KB (262160 bytes)
MD5: dba6689c1423c4387449c2ac6686c8e4
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Desktop
Group: Malware file
Last Updated: October 3, 2011
winupdate86.exe File name: winupdate86.exe
Size: 24.06 KB (24064 bytes)
MD5: 12f88b44d471fc3b93468d5d5b8d428c
Detection count: 13
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
winupdate86.exe File name: winupdate86.exe
Size: 24.06 KB (24064 bytes)
MD5: 9b67c07f189a296d2ab5400525e51220
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
%APPDATA%\winantiviruspro2006freeinstall_nl[1].exe File name: winantiviruspro2006freeinstall_nl[1].exe
Size: 92.88 KB (92880 bytes)
MD5: b56edb2b32396c4e44222f12fc630d83
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: November 1, 2011
winupdate86.exe File name: winupdate86.exe
Size: 22.01 KB (22016 bytes)
MD5: de4a872ee7abd0ef6dd4187c49e7dcf5
Detection count: 11
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
winupdate86.exe File name: winupdate86.exe
Size: 22.01 KB (22016 bytes)
MD5: 48b6e39590da6ba36da9a02b86aeebf9
Detection count: 10
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 15, 2010
%APPDATA%\newsoftwareinstaller[1].exe File name: newsoftwareinstaller[1].exe
Size: 144.15 KB (144152 bytes)
MD5: 6b45cbb5ff302933b36aaadfe2fbff42
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: September 21, 2011

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{376892AE-1825-4E5F-9F85-23F9640051CC}{94204837-0871-4E6A-A426-7F75B1B731F0}File name without pathmsa.exesmss32.exeHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Toolbar\{12A25CE9-0A93-4074-9516-A5B1A83141C9}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{FCCD9F7B-5BF3-4DC4-B131-CE069F8A62AB}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{FF20AF38-AD56-4361-AE03-339130767E26}

Additional Information

The following URL's were detected:
cubeexe.comsecurityonlinecomputer.net

One Comment

  • Gray Smythe says:

    This spyware antivirus package was installed on my firm\'s computer by an IT Security Expert trading as Ashurst Group LTD (company did not exist at Companies House) in London/Surrey. This guy claimed to be from MI5 & \'found\' syp wireless devices & other such nonsense designed to extort cash from my clients.

Loading...