Troj/FakeAV-AFE is a Trojan for the Windows platform.
Troj/FakeAV-AFE includes functionality to:
- perform actions that may cause a system to crash
- copy itself to the <WINDOWS>\system32 directory
- create files in the <WINDOWS>\system32 directory
- steal confidential information
When Troj/FakeAV-AFE is installed random files such as the following are created:
<System>\10009t5zj799.exe
<System>\10696haczto5l2f0.dll
<System>\107955zambot1499.dll
<System>\109599irusz8a5.cpl
<System>\1116zsp5mbot1c39.dll
<System>\11482h5cktool596z.bin
<System>\11569ha9k5ooz1db.bin
<System>\1191ha5ktooz3a2.ocx
<System>\125ct9izf1675.bin
<System>\130035ot-9-viruszbf.cpl
<System>\1330zspambo529b.dll
<System>\1333z5irus7c9.exe
<System>\13785z9rus20e.ocx
<System>\139ezh5eat13299.bin
<System>\143es59alz110.ocx
<System>\14987wzrm6d25.exe
<System>\14992spambz56ca.ocx
<System>\15339zt-a-5irus474.cpl
<System>\15757vizus9c55.exe
<System>\1575zvirus89.bin
<System>\15767ziru599.dll
<System>\15865vz9usaa.bin
<System>\15895troj779z.dll
<System>\15962hzcktool295.ocx
<System>\15bfspzware9864.ocx
<System>\1633t95zat24747.dll
<System>\1659zvir5s5a9.dll
<System>\166av9r3582z.bin
<System>\170495zo97d0.cpl
<System>\1725szarse955.cpl
<System>\1755spy4zc9.cpl
<System>\17580troz9f6.ocx
<System>\18194vzrus625.cpl
<System>\1871695y54z.exe
<System>\18e45tza93135.exe
<System>\18e89h5ef12z2.cpl
<System>\190z8spy5a.exe
<System>\19195tr5j77z.ocx
<System>\1946spy6d5z.dll
<System>\1959zspa5bot5f6.ocx
<System>\19859hacktzol2ca.ocx
<System>\19959vi5us2z.exe
<System>\199ev5r273z.dll
<System>\1aathiez9511.cpl
<System>\1b09vi958z5.dll
<System>\1b9espy9arz1350.exe
<System>\1bd2ad5warez97.exe
<System>\1becspy5are39z3.exe
<System>\1bz0thief15389.exe
<System>\1d4a9hreat18537z.dll
<System>\1d5dstez95483.dll
<System>\1z0thief57599.cpl
<System>\1z6dspywar910285.ocx
<System>\20547vi9zs4a5.ocx
<System>\20z96not5a-virus49b.dll
<System>\2105sz9647.bin
<System>\21557spy7zb9.cpl
<System>\215bdoz9lo5der554.ocx
<System>\2175stz9l907.bin
<System>\21z9viru5909.ocx
<System>\22086tz9519.exe
<System>\222z9s5y555.cpl
<System>\22447spa5boz5b9.cpl
<System>\2256zw9rm58.ocx
<System>\22995ackzoor1476.cpl
<System>\231zs5ar9e2428.cpl
<System>\2345vzrus5f9.bin
<System>\23553troj6z29.cpl
<System>\2355st9al16z0.cpl
<System>\23757worm309z.exe
<System>\24351tzoj92b.bin
<System>\24489zpambot5cc9.ocx
<System>\24554w59z313.dll
<System>\24795troj353z.bin
<System>\24909szy1ae5.cpl
<System>\25362z5rm519.ocx
<System>\2555t9zj781.dll
<System>\255975ozm6e8.bin
<System>\256fad9ware2154z.ocx
<System>\25944zor95fc.exe
<System>\25972wor53bz.dll
<System>\2621virzs539.ocx
<System>\26851not-a-z5rus299.bin
<System>\2695ha5kto9z31b.exe
<System>\26e59ddware27z9.bin
<System>\2702b9ckdoor2955z.ocx
<System>\27784h5cktool5zb9.cpl
<System>\283z95ot-a-virus48b.cpl
<System>\28475vir9s3f7z.exe
<System>\28514spam5o94zb.bin
<System>\28625spazbot1989.exe
<System>\2871459oj5dz.ocx
<System>\2877thief895z.exe
<System>\29353worm9zf.bin
<System>\293z3vi9u529a.exe
<System>\29497not-a-virzs765.dll
<System>\29549tr5j66z.bin
<System>\29669wzrm555.dll
<System>\29791vzrus52a5.cpl
<System>\297z5not-a-virus91.ocx
<System>\2995backzo5r188.cpl
<System>\29971vi5usz24.ocx
<System>\29986n5t-a-vzr9s725.bin
<System>\29c4v5r2z43.bin
<System>\29z17troj548.cpl
<System>\2a55backd9or155z.dll
<System>\2addvir2529z.ocx
<System>\2adfdow9loade5223z.exe
<System>\2b09viz3035.dll
<System>\2c45v9z2030.ocx
<System>\2e3zba9kdo5r998.cpl
<System>\2f89vir851z.ocx
<System>\2z03959t-a-virus663.exe
<System>\2z581hackto9l237.bin
<System>\2z5esp9rse1067.bin
<System>\2z69hacktoo9521.dll
<System>\2z782not5a-v9rus518.cpl
<System>\2z939hacktool6f5.ocx
<System>\2zf5downlo5der3139.ocx
<System>\3049downlzade59136.cpl
<System>\30568troz792.exe
<System>\306705roj9z0.bin
<System>\3070495oz546.cpl
<System>\30913sp5mbz956c.ocx
<System>\30963worm758z.cpl
<System>\31926hac5tool10z.ocx
<System>\31928troj55z.cpl
<System>\31fca95zare157.dll
<System>\3251zi52859.bin
<System>\3397t5oz7e9.exe
<System>\33a29irz52.dll
<System>\342zstea92655.cpl
<System>\355ebackzo9r905.ocx
<System>\356espa5s924z3.dll
<System>\356znot-a9virus749.bin
<System>\35a2thi9z585.cpl
<System>\3671b5czdo9r2859.exe
<System>\3751baz9door2005.ocx
<System>\3799viz553.dll
<System>\390bbackdoorz959.dll
<System>\394n9t-a5virus39z.dll
<System>\3958zpyware2048.exe
<System>\396cbackd5or1312z.cpl
<System>\39782hacztool7b5.cpl
<System>\398bs5eal155z.exe
<System>\39e4spywa5e997z.ocx
<System>\39f5threat250z5.exe
<System>\3a2c9hiez1590.ocx
<System>\3b56thief3z809.cpl
<System>\3d2c59arse2804z.bin
<System>\3fe9spzwa5e1959.dll
<System>\3z201n95-a-virus2d2.exe
<System>\3z2825pa9bot173.bin
<System>\3z95steal2848.exe
<System>\4079zo5m63d.bin
<System>\4083thi9f1995z.dll
<System>\41czb9ckdo5r303.ocx
<System>\42585ot-a-virzs2299.bin
<System>\4360threzt59309.cpl
<System>\4545addwar928z6.dll
<System>\4569zteal710.cpl
<System>\459sp9351z.exe
<System>\45b99zdwar51244.bin
<System>\45cfaddware2698z.exe
<System>\4600stzal1695.bin
<System>\4676bac9doorz53.bin
<System>\4757addwzre19945.ocx
<System>\4793zddware354.exe
<System>\486zvi93573.bin
<System>\4996thzef573.bin
<System>\49ccspy5a9e2z06.cpl
<System>\4a3dba5z9oor1929.ocx
<System>\4cd8tzi9f5059.ocx
<System>\4cf1d5wnloa9ez2555.exe
<System>\4cz5s9arse2990.dll
<System>\4dffzte9l2590.ocx
<System>\4e0ebz5kdo9r571.exe
<System>\4f3ctzrea5108079.ocx
<System>\4f5cdo9nloader251z.dll
<System>\4z10th9e5t8627.dll
<System>\4zaspyware2954.bin
<System>\50b4thi9f1z66.bin
<System>\510509acktozl5e4.cpl
<System>\5108addzar92150.ocx
<System>\516estealz926.exe
<System>\5174v5r2z819.dll
<System>\51caad9ware231z.ocx
<System>\51f39pz5are1659.ocx
<System>\52187v9rus523z.bin
<System>\525ds9ywarz1447.exe
<System>\536not-z-5irus698.bin
<System>\5388hackt95z2a5.cpl
<System>\5393spambot3zb9.exe
<System>\5471t5reat9z899.cpl
<System>\54c9downl5ader225z.cpl
<System>\55a6zddwa9e2743.dll
<System>\55dowzloa9er1919.bin
<System>\55fethiefz95.ocx
<System>\55fezdd9are1908.ocx
<System>\5613sp9zbotb3.bin
<System>\5641threzt94686.dll
<System>\568aadz59re3100.dll
<System>\56f9spywarz3259.ocx
<System>\57550s9azbot1f6.dll
<System>\579b9hief3z35.ocx
<System>\5827w9zm435.bin
<System>\5828backz5or1799.cpl
<System>\5890zwo9m62a.dll
<System>\5925thief313z.dll
<System>\5945thiefz598.exe
<System>\59493wozm1ac.bin
<System>\598ethreaz21705.dll
<System>\59988szy50c.ocx
<System>\599s5y9ez.exe
<System>\59f0vz92667.bin
<System>\59z58vi9us37e.cpl
<System>\5a43vi91016z.dll
<System>\5b56t9reat2z521.dll
<System>\5ba5t9izf758.dll
<System>\5bddazdwar9343.cpl
<System>\5c9athreatz1244.dll
<System>\5e98thrzat949.cpl
<System>\5ez5thief3291.dll
<System>\5ezfad9ware5735.bin
<System>\5f00backdoorz997.bin
<System>\5z92threat752.dll
<System>\6060z5rm7e39.exe
<System>\6192z5yware3925.dll