Home→Descriptions→Trojan.Win32.FakeAV.eya
| Detected | Sep 07 2010 17:09 GMT |
| Released | Sep 07 2010 23:30 GMT |
| Published | Oct 26 2010 12:18 GMT |
This Trojan simulates an anti-virus program in order to obtain remuneration from the user for the detection and deletion of false threats. It is a Windows application (PE EXE file). It is 1 134 592 bytes in size. It is written in C++.
Once launched, the Trojan moves its body into the following file:
%USERPROFILE%\Local Settings\Application Data\<rnd>.exewhere <rnd> is a random six-digit decimal number.
To ensure that the copy created is launched automatically each time the system is rebooted, the following system registry keys are created:
[HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce] "<rnd>" = ""%USERPROFILE%\Local Settings\Application Data\<rnd>.exe" 0 47" [HKU\S-1-5-21-606747145-1060284298-839522115-1003 \Software\Microsoft\Windows\CurrentVersion\RunOnce] "<rnd>" = ""%USERPROFILE%\Local Settings\Application Data\ <rnd>.exe" 0 47"The Trojan then displays the following message:

The Trojan then launches a previously created copy for execution and ceases running.
Once launched, the Trojan performs the following actions:
[HKLM\System\CurrentControlSet\Hardware Profiles\0001 \Software\Microsoft\windows\CurrentVersion\Internet Settings] "ProxyEnable" = "0" [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "MigrateProxy" = "1" "ProxyEnable" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyServer" "ProxyOverride" "AutoConfigURL"This modifies Internet Explorer's proxy server settings.








77.***.124
If your computer does not have antivirus protection and has been infected by this malicious program, follow the instructions below to delete it:
%USERPROFILE%\Local Settings\Application Data\<rnd>.exe
[HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce] "<rnd>" = ""%USERPROFILE%\Local Settings\Application Data\<rnd>.exe" 0 47" [HKU\S-1-5-21-606747145-1060284298-839522115-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce] "<rnd>" = ""%USERPROFILE%\Local Settings\Application Data\<rnd>.exe" 0 47"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings] "ProxyEnable" [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "MigrateProxy" "ProxyEnable" [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "ProxyServer" "ProxyOverride" "AutoConfigURL"
MD5: 1557EF468DBDA9E0A917571CFCDFD2CF
SHA1: FC1598BBE28EA47C1B361EAD8AF3CCD395298866
This type of behaviour covers malicious programs that delete, block, modify, or copy data, disrupt computer or network performance, but which cannot be classified under any of the behaviours identified above.
This classification also covers “multipurpose” Trojan programs, i.e. those that are capable of conducting several actions at once and which demonstrate several Trojan behaviours in a single program. This means they cannot be indisputably classified as having any single behaviour.