Threat Database Trojans Trojan.Agent/Gen-FakeDoc

Trojan.Agent/Gen-FakeDoc

By LoneStar in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 5
First Seen: November 22, 2011
Last Seen: February 10, 2022
OS(es) Affected: Windows

Trojan.Agent/Gen-FakeDoc is a seditious Trojan which is able to obtain remote access to the infected computer system. When on a compromised PC, Trojan.Agent/Gen-FakeDoc will show annoying pop-up ads and fake security alerts. Trojan.Agent/Gen-FakeDoc can disable firewall and lead to identity theft. Trojan.Agent/Gen-FakeDoc can chnage you web browser settings and reroute your default homepage to suspicious web pages. Eliminate Trojan.Agent/Gen-FakeDoc immediately after detection.

File System Details

Trojan.Agent/Gen-FakeDoc may create the following file(s):
# File Name Detections
1. vmitla1.exe
2. moomqojucfqbs.dll
3. GetModule36.exe
4. TubePlayer[1].ver.6.exe
5. nvvsvc.exe
6. freereg.exe
7. CDDBUIRoxio32.dll
8. 8[1].exe,_ad9.exe
9. systeminit.exe
10. ayscjcts.exe
11. d3dx9_2832.dll
12. TfoQAsn4.exe
13. AUTOPLAY.EXE
14. WgaLogon.dll
15. 2d6smh6a.exe
16. DesktopTool.exe
17. crypts.dll
18. TubePlayer.ver.6.exe
19. sysfnx.exe
20. ccodr.exe
21. baw7.tmp
22. yiklrfqsko.dll3>

Registry Details

Trojan.Agent/Gen-FakeDoc may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\WMFMRNV
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\net64
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\netw
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\runsql
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\UpdateWin
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\\Winlogon\Notify\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\windmh32
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DameWare NT Utilities 2.6Microsoft\Windows\CurrentVersion\Run\IEUpdate
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\netsv32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\netzip
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\IEUpdate
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\mbssm32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\cluhtj
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\netc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\netx
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\UpdateWin

Trending

Most Viewed

Loading...