W32/TDSS.AHCR Trojan
| Name |
W32/TDSS.AHCR Trojan |
| Aliases |
Mal/FakeAV-GQ, Rogue:Win32/FakeRean |
| Updated on |
January 21 2012 |
Virus Information - W32/TDSS.AHCR Trojan:
W32/TDSS.AHCR is a trojan. The trojan will infect Windows systems.
Upon execution, the trojan drops the following file
wta.exe in Documents and Settings\Default User\Application Data.
And the trojan also drops the following file
ctfmon.exe in WINDOWS\system32.
The trojan modifies registry at the following location:
HKEY_USER\S-1-5-21-XXXXXXXXX-XXXXXXXXXX-XXXXXXXXX-XXXX\Software\Microsoft\Windows\CurrentVersion\run

|