|
Tro.AntiSpywareScam.B Trojan Information
| Name: |
Tro.AntiSpywareScam.B |
| Category: |
Trojan |
| Alias: |
- Alias: BackDoor-AJW trojan, BackDoor-AJW, Backdoor.Antilam.20.j |
| Advice: |
Remove |
| Risk: |
High Risk
High risk threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction. May open up communication ports, use polymorphic tactics, stealth installations, and/or anti-spy counter measures. May use a security flaw in the operating system to gain access to your computer. |
| Description:
|
Tro.AntiSpywareScam.B includes a group of files used with rogue security/anti-spyware programs such as RazeSpyware.
Tro.AntiSpywareScam.B causes RazeSpyware to stealth install, changes the desktop background to display false warnings of spyware on the computer, spawns pop-up messages from the system tray with false warnings of nalware/spyware infections and installs a browser helper object (BHO). This trojan will also install a file that causes a false warning tha the computer is infected with a virus infection named xxxdialer.exe, supposedly a "Universal Porn Dialer".
|
| Signatures:
|
process: ntpnt.exe: MD5 Hash: e6d22ca25fb818b1355...
process: xxxdialer.exe: MD5 Hash: 27b05eeb723f3cd6a86...
process: mswinf32.exe: MD5 Hash: 2c015b7fc7c7212d4b6...
process: mswinb32.exe: MD5 Hash: fa460800d78349e4a8e...
process: intxt.exe: MD5 Hash: 6768decb14072356f7e...
process: shell386.exe: MD5 Hash: 2490050cd5f6b5adf58.. |
| Type: |
Trojan - A Trojan software is any software on a user's computer that the user is not aware or intentionally installed. Most Trojan software is designed to perform some sort of actions that could jeopardize the user's security or privacy. |
Top Trojan Visited Pages:
Tro.Downloader.loadadv - 410 visits
Enable Regedit - 192 visits
Java.ClassLoader.Dummy.d - 184 visits
Trojan.BankerSpy - 178 visits
RBot.steam - 86 visits
Startup.NameShifter.Xgtray - 77 visits
Tro.Bagle.SP - 59 visits
LRPatch Trojan - 57 visits
Trojan.BHO.NameShifter.EZ - 55 visits
Tro.YourStartingPage - 54 visits
Random Trojan Pages:
Virus.StalkerX.650
IRC.Microb.b - Alias: Backdoor.IRC.Microb.b
BO 2K Sniper
Viru.449.Batch
Telnet Junkie
Virus.CleanLogs - Alias: CleanIISLog
Trojan.Downloader CRK
Hat - Alias: BackDoor-CY, Backdoor.HackTack.2K.c
Trojan.Startup.NameShifter.FQ
AntiLam 2.0 - Alias: BackDoor-AJW trojan, BackDoor-AJW, Backdoor.Antilam.20.j
|