Threat Database Trojans Troj/VB-FPL

Troj/VB-FPL

By GoldSparrow in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 1
First Seen: October 11, 2011
Last Seen: April 23, 2020
OS(es) Affected: Windows

The Troj/VB-FPL Trojan is a fairly typical Trojan infection that makes harmful changes to the Windows Registry and installs malicious software onto the infected computer. The Troj/VB-FPL Trojan, in particular, has been closely associated with several distinct strains of Adware. While this Trojan infection is thought to have been created in 2008, Troj/VB-FPL made headlines in 2011 when Troj/VB-FPL was used in a widespread spam email scam.

The Troj/VB-FPL Trojan and the YesAsia.com Scam

YesAsia.com is a website dedicated to selling products, mainly music, electronics and videos to Asian audiences. It would be fair to compare it to Amazon, although aimed at consumers in Asian countries. Criminals have sent out a large quantity of spam emails containing a compressed attachment that, when opened, infects the victim's computer with the Troj/VB-FPL Trojan. These spam emails are designed to look like invoices from YesAsia.com. The victim will typically receive a fake invoice from YesAsia.com claiming that a specific item was bought. The email will instruct the victim to open the attached .zip for more details. ESG PC security researchers warn against opening this attachment, or any other unknown email attachments. When this .zip file is opened, it will actually infect the victim's computer system with the Troj/VB-FPL Trojan. This Trojan, in turn, may infect the victim's computer with Adware or allow a hacker to gain access to the infected operating system. Using the Troj/VB-FPL Trojan, a criminal can install a Remote Access Tool onto the infected computer. This can allow the criminal to control the infected computer system from afar, with the help of automated software. Using this kind of malware, the infected computer can, in turn, be used to send out additional spam email so that more victims become infected with the Troj/VB-FPL Trojan.

Avoiding a Troj/VB-FPL Trojan Infection

There are several steps you can take to avoid a Troj/VB-FPL Trojan infection. ESG PC security researchers strongly recommend using fully-updated security applications and a strong anti-spam filter for your email account. Having a real-time anti-virus scanner and a strong firewall can help prevent Trojan infections. However, the most important thing you can do to prevent a Troj/VB-FPL Trojan infection is simply to avoid opening suspicious emails and learning to identify the characteristics of a typical spam email. Most importantly, it is essential to avoid downloading email attachments from unexpected senders

SpyHunter Detects & Remove Troj/VB-FPL

File System Details

Troj/VB-FPL may create the following file(s):
# File Name MD5 Detections
1. C:\Documents and Settings\\Application Data\newegg.exe
2. Invoice-Y4C20111010C.zip de24db11baedf78ea225bd24e02aec7f 0
3. Invoice-Y4C20111010C.zip 32cd46571103505d4e8d3792c9940d0f 0

Registry Details

Troj/VB-FPL may create the following registry entry or registry entries:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run
HKCU\Software\VB and VBA Program Settings\INSTALL\DATE
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile

Trending

Most Viewed

Loading...