subject: How to Detect and Rmove the Trojan.FakeAV [print this page]
[removed]// var addthis_config = {"data_track_clickback":true};
// ]]>[removed]
[removed][removed]
1. What is the Trojan.FakeAV
Trojan.FakeAV is a malicious trojan horse that may represent a high security risk for the compromised system or its network environment. Trojan.FakeAV, also known as Trojan.Win32.Small.ccz, creates a startup registry entry and may display annoying fake alerts of malware payloads in order to persuade users to buy rogue antispyware products. Trojan.FakeAV contains characteristics of an identified security risk and should be removed once detected.
a. File System Modifications
%CommonFavorites%\_favdata.dat
%Temp%eapp32hst.dll
%Temp%PRAGMAb224.tmp
%Temp%PRAGMAb253.tmp
%Temp%PRAGMAc84c.tmp
%Temp%TMP43307.tmp
%Temp%opwesitjh
%Temp%wscsvc32.exe
%Windir%PRAGMAsesmccxtirPRAGMAc.dll
%Windir%PRAGMAsesmccxtirPRAGMAcfg.ini
%Windir%PRAGMAsesmccxtirPRAGMAd.sys
%Windir%PRAGMAsesmccxtirPRAGMAsrcr.dat
Notes: %CommonFavorites% is a variable that refers to the file system directory that serves as a common repository for all users' favorite items. A typical path is C:Documents and SettingsAll UsersFavorites (Windows NT/2000/XP).
%Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:Documents and Settings[UserName]Local SettingsTemp (Windows NT/2000/XP).
%Windir% is a variable that refers to the Windows installation folder. By default, this is C:Windows or C:Winnt.
The following directory was created: %Windir%PRAGMAsesmccxtir
a. Please updatethe policy basic knowledge of Sax2 in time, Once sax2 detects the communication of these trojans, it will break them and ensure your network & business security.
b. How to Remove the Trojan.FakeAV Manually?
Step 1 : The associated files of Trojan.FakeAV to be deleted are listed below:
[HKEY_LOCAL_MACHINESOFTWAREClasses*]
Step 2 : The registry entries of Trojan.FakeAV that need to be removed are listed as follows:
File NameFile SizeMD5
CLADD
2560
e229a2fa3acd3f307ede63b89db833a4
WI3e94.exe
1943552
02fed38ea8975716f5f8f2595f905010
ddexpshare.exe
790528
8b4840953e5511d0a08ee67ff0034e2c
services.exe
47616
da9976cd71469bbcf0f87ec40e2ce798
c. How to Remove these trojans Instantly?
Malwarebytes' Anti-Malware is an anti-malware application that can thoroughly remove even the most advanced malware. It includes a number of features, including a built in protection monitor that blocks malicious processes before they even start. visit http://www.ids-sax2.com/Malwarebytes-Anti-Malware.htm and download Malwarebytes' Anti-Malware to help you.
3. Appendix
For more information, please visit http://www.ids-sax2.com/ComputerSecurityNewsletter.htm