Protector Plus Download Antivirus
Home
Download Antivirus
Antivirus Products
Order Antivirus


Antivirus Software for Windows XP/2000/2003
Antivirus Software for Windows Me/98
Antivirus Software for Exchange 2000/2003
Antivirus Software for NetWare

W32/FakeAV.EB Trojan

Name W32/FakeAV.EB Trojan
Aliases TROJ_FAKEAV.EB
Discovered on August 27, 2008

 Virus Information - W32/FakeAV.EB Trojan:

W32/FakeAV.EB is a trojan. The trojan will infect Windows systems.

The trojan may be dropped by other malware or may be downloaded from remote website by other malware. It may also be downloaded unknowingly by a user while visiting malicious Website.

Upon execution, the trojan drops the following files:

database.dat in the %Program Files%\rhc7pgj0e3ct folder,
license.txt in the %Program Files%\rhc7pgj0e3ct folder,
MFC71.dll in the %Program Files%\rhc7pgj0e3ct folder,
MFC71ENU.DLL in the %Program Files%\rhc7pgj0e3ct folder,
msvcp71.dll in the %Program Files%\rhc7pgj0e3ct folder,
msvcr71.dll in the %Program Files%\rhc7pgj0e3ct folder,
rhc7pgj0e3ct.exe in the %Program Files%\rhc7pgj0e3ct folder,
rhc7pgj0e3ct.exe.local in the %Program Files%\rhc7pgj0e3ct folder,
Uninstall.exe in the %Program Files%\rhc7pgj0e3ct folder,
Antivirus XP 2008.lnkin the Documents and Settings\All Users\Desktop,
phc3pgj0e3ct.bmp in the Windows System folder,
pphc3pgj0e3ct.exe in the Windows System folder,
Antivirus XP 2008.lnk in the %User Profile%\Application Data\Microsoft\Internet Explorer\Quick Launch.


The trojan modifies registry at the following locations to load itself during each startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphc3pgj0e3ct
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SMrhc7pgj0e3ct


It also modifies registry at the following locations:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\rhc7pgj0e3ct
HKEY_CURRENT_USER\Control Panel\Desktop\SCRNSAVE.EXE
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_CURRENT_USER\Software\Sysinternals\Bluescreen Screen Saver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier
HKEY_CURRENT_USER\Control Panel\Colors\Background
HKEY_CURRENT_USER\Control Panel\Desktop\ConvertedWallpaper
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\DisableSR


The trojan modifies the system wallpaper and screensaver.

Anti virus for Windows Download Now!


Home Page Download Antivirus Antivirus Products Order Antivirus

Copyright © 2008 Proland Software.All rights reserved

antivirus software, anti virus software, anti virus, download antivirus, download anti virus, free antivirus, free anti virus, antivirus, download, free, windows, windows xp, xp, sp2, windows me, windows 2000, 98, 95, nt, me, 2003, netware, anti-virus, virus, worm, trojan, protector, plus, proland, virus software, spyware