Home Malware Programs Trojans Trojan.FraudPack

Trojan.FraudPack

Posted: February 29, 2008

Threat Metric

Threat Level: 9/10
Infected PCs: 1,698
First Seen: July 24, 2009
Last Seen: January 23, 2022
OS(es) Affected: Windows

Trojan.FraudPack is a Trojan that delivers rogue security applications onto your PC. Like many Trojans, Trojan.FraudPack has been observed to use browser exploits and malicious advertising scripts to infect new computers without consent. Rogue security programs distributed by Trojan.FraudPack are known to cause many different problems such as preventing applications from running, hijacking web browsers to redirect you to dangerous websites, creating fake infection alerts and corrupting the Windows Registry. Removing Trojan.FraudPack should be a natural part of an overall system scan that removes Trojan.FraudPack's rogue security programs from your computer, since removing the threat while leaving Trojan.FraudPack intact will not solve the root of your problems.

Trojan.FraudPack is Just a Chauffeur for Fake Security Software

Trojan.FraudPack is the seedy side of rogue security anti-virus programs that the criminals don't want you to know about – although the rogue security programs delivered by Trojan.FraudPack are all obnoxiously visible, Trojan.FraudPack itself is well-hidden, being a clear sign of hostile intent that ruins the atmosphere of the scam. Trojan.FraudPack is known to distribute rogue security applications like Antivirus Monitor, Antivirus Soft, Antimalware GO, Antivirus .NET, AntiVira AV and many more.

Trojan.FraudPack will try to infect your computer through hostile scripts that are hosted on dangerous websites or embedded in dangerous advertisements. Disabling Flash and JavaScript will help you reduce the vectors for Trojan.FraudPack infections, but even these actions can't keep your computer completely safe. Interacting with the websites or advertisements in question isn't always necessary; sometimes, all that's needed is for the website or advertisement to load.

The main purpose of a Trojan.FraudPack infection is to download and install (or 'drop') one of the above rogue security programs on your PC, sometimes through the use of fake errors imitating Windows alerts. After this, the rogue security program takes up most of the limelight, creating countless fake infection alerts and other system problems. Although the threat will persistently try to get you to spend money on an activation key, following along with Trojan.FraudPack's plan will only harm your computer and your finances.

Clearing Out the Pack of Frauds

You may experience other problems while Trojan.FraudPack and Trojan.FraudPack's rogue security applications are on your PC. The most common symptoms include:

  • Fake security program infections that result in the program crashing when you try to launch it. Rogue security applications will do this to avoid any possibility of real anti-malware software detecting them. One possible error that's used by Trojan.FraudPack-related infections contains the following text:

    "Application cannot be executed. The file [executable file] is infected. Do you want to activate your anti-virus software now?"

  • Browser hijacks that control your browsing habits. You may see an error that stops you from visiting a website related to PC security, or you may be redirected to the rogue security product's homepage.

Deleting Trojan.FraudPack along with any other malware Trojan.FraudPack dropped on your PC should be considered absolutely required for insuring your computer's privacy. Attempting to find and remove Trojan.FraudPack yourself is a difficult task that is best reserved for situations where all other solutions have failed.

Rather than taking the hard option, go easy on yourself and use an actual anti-malware program to hunt down and take out Trojan.FraudPack for you. Switching to Safe Mode may be necessary to stop Trojan.FraudPack from avoiding its imminent destruction.

Aliases

Trojan.FraudPack [Ikarus]PUP/Win32.Helper [AhnLab-V3]TR/FraudPack.R.7 [AntiVir]Win32:PUP-gen [PUP] [Avast]Artemis!BF6D991EA7F0 [McAfee]Generic19.MSP [AVG]W32/FraudPack.BJVJ!tr [Fortinet]VirTool.Win32.Obfuscator.ah!k (v) [Sunbelt]Win-Trojan/Fraudpack.245760.L [AhnLab-V3]TR/FraudPack.bjvj [AntiVir]Trojan.Fakealert.18898 [DrWeb]Mal/FakeAV-DO [Sophos]Trojan.Generic.KDV.36266 [BitDefender]Trojan.Win32.FraudPack.bjvj [Kaspersky]Trojan.Fraudpack-4748 [ClamAV]
More aliases (714)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%LOCALAPPDATA%\asam.exe File name: asam.exe
Size: 61.18 KB (61184 bytes)
MD5: 25ecbaf37ead446a21c6211f91202d6c
Detection count: 239
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: September 28, 2010
%USERPROFILE%\Start Menu\Programs\Startup\svchost.exe File name: svchost.exe
Size: 40.44 KB (40448 bytes)
MD5: 17ff88f8799d0af3f2128ec88b39ba5f
Detection count: 171
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: September 23, 2010
%TEMP%\yxxa.exe File name: yxxa.exe
Size: 40.96 KB (40960 bytes)
MD5: 299e2c761ef22b6871cf4e3311ec12c1
Detection count: 133
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: October 25, 2010
cmkisftav.exe File name: cmkisftav.exe
Size: 254.72 KB (254720 bytes)
MD5: f0b39bf0680c49be9db495194da0cc13
Detection count: 96
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 12, 2010
iehelper.dll File name: iehelper.dll
Size: 12.03 KB (12032 bytes)
MD5: 86006664d9eb37291e628ace29dbbbd3
Detection count: 93
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
fbabj220320.exe File name: fbabj220320.exe
Size: 125.95 KB (125952 bytes)
MD5: feca00f7774ea296a20a8acc3aa2dcd5
Detection count: 82
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 26, 2010
msxmlm.dll File name: msxmlm.dll
Size: 403.45 KB (403456 bytes)
MD5: 7fe4e95df7cd7c819de8eca2490cb99e
Detection count: 66
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
laensftav.exe File name: laensftav.exe
Size: 278.78 KB (278784 bytes)
MD5: 544f1888d43321239ff5a5f401b53bc5
Detection count: 64
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 18, 2010
cbsd.exe File name: cbsd.exe
Size: 117.24 KB (117248 bytes)
MD5: b1b918784bf726283f9b93ea399b337e
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 18, 2010
UpdateCheck.dll File name: UpdateCheck.dll
Size: 619.52 KB (619520 bytes)
MD5: 5e61c8e678d821b5ac9ca80dbb0a781b
Detection count: 54
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: April 3, 2010
win32extension.dll File name: win32extension.dll
Size: 378.36 KB (378368 bytes)
MD5: 34d13d479446dcf6fa828b252312d278
Detection count: 53
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: April 3, 2010
%LOCALAPPDATA%\tnmmokolq\tsvswvcuqiw.exe File name: tsvswvcuqiw.exe
Size: 245.24 KB (245248 bytes)
MD5: e6bcc2e1376b7b97d5ee63989c6a6996
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\tnmmokolq
Group: Malware file
Last Updated: November 12, 2010
%USERPROFILE%\Local Settings\Application Data\Microsoft\PinGuide\PinGuideUDF.exe File name: PinGuideUDF.exe
Size: 379.9 KB (379904 bytes)
MD5: bf6d991ea7f0d4471173d3a3003f3bd0
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data\Microsoft\PinGuide
Group: Malware file
Last Updated: June 15, 2012
msh.exe File name: msh.exe
Size: 139.26 KB (139264 bytes)
MD5: 66b3ad51a6be6c072b1145253d895ab0
Detection count: 20
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
%WINDIR%\PRAGMAfpcioufnlq\PRAGMAd.sys File name: PRAGMAd.sys
Size: 52.22 KB (52224 bytes)
MD5: f775d72d8b8a217c890cf7d7fa20d087
Detection count: 16
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\PRAGMAfpcioufnlq
Group: Malware file
Last Updated: November 2, 2010
%LOCALAPPDATA%\gpmtwjyre\rinhhgkuqiw.exe File name: rinhhgkuqiw.exe
Size: 245.76 KB (245760 bytes)
MD5: 502ed77e17e0a1f4ef6f2cfe3c208c85
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\gpmtwjyre
Group: Malware file
Last Updated: November 12, 2010
~33.dll File name: ~33.dll
Size: 219.13 KB (219136 bytes)
MD5: c33209714fef6beb4cdca1867eda7716
Detection count: 12
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: January 8, 2010
%LOCALAPPDATA%\xmtdyy\ngtcwo.exe File name: ngtcwo.exe
Size: 343.29 KB (343296 bytes)
MD5: 57d17b820453114f47081e2ef1def4e4
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\xmtdyy
Group: Malware file
Last Updated: November 2, 2010
settdebugx.exe File name: settdebugx.exe
Size: 716.8 KB (716800 bytes)
MD5: ab1ca14bf5cbf5dd0d4cc68e4d6778b5
Detection count: 10
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 8, 2010
lovebudo.dll File name: lovebudo.dll
Size: 49.66 KB (49664 bytes)
MD5: d56e1377ac6d1ecca82b63944f48f542
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}

Related Posts

Loading...