Trojan.Win32.Fraudpack.amau
Threat Name: Trojan.Win32.Fraudpack.amau
Description as :Trojan.Win32.Fraudpack.amau in C:\Documents and Settings\Local Settings\TEMP\7.682492419092743E8.EXE. Kaspersky seems to have quarantined it the day it detected it. But the next day it pops up again multiple times, along with the following:
Trojan.Win32.FraudPack.ambs in C:\Documents and Settings\Local Settings\TEMP\2.0650159810297944E7.EXE
Trojan.Win32.FraudPack.ambs in C:\Documents and Settings\Local Settings\Application Data\av.exe
Trojan.Win32.FraudPack.ambs in C:\Documents and Settings\Local Settings\Application Data\MSASCui.exe
Trojan.Win32.FraudPack.amau in C:\Documents and Settings\Local Settings\Application Data\mtg.exe
Trojan. Downloader - C:\WINDOWS\system32\braviax.exe
Spread Method:
E-Mail
Malware Installation
Threat type:Trojan.Win32
Trojan.Win32.Fraudpack.amau first detected:2010-02-28
Virus file known is PE EXE file written in Java
File Size:342K Bytes.
Behavior:Propagation via P2P networks
Level of Spread:3
Level of Threat:4
Reported Path:c:\System Volume Information\ _restore…\
MD5:A28WXNGMvS7Bt8BxRX3npEWDmk1Sk3s3
SHA1..:iPAeguot1b7J00j8aGQ78mfl76Mb6R053xI22dv1
Alias:
McAfee :Trojan.Win32.Agent.amgl
BitDefender :AdWare.Win32.SuperJuan.dpo
QuickHeal:Trojan.Win32.Midgare.ocq
Report Countries:
Ukrainian
Bulgaria
Bolivia
Australia
United States
Trojan.Win32.Fraudpack.amau Removal instructions:
Restart to safe mode
Run a whole scan
How to remove Trojan.Win32.Fraudpack.amau :
1.Delete the IE temporary files.
2.Update antivirus database and run a full scan.
Need help? Post you problem on Free Malware Remove Help forum
Trojan.Win32.Fraudpack.amau Summary
1.Temporarily Disable System Restore;2.Reboot computer in SafeMode;3.delte Trojan.Win32.Fraudpack.amau virus files and kill Trojan.Win32.Fraudpack.amau file task process(if have);4.Delete/Modify any values added to the registry by Trojan.Win32.Fraudpack.amau ;5.delete IE temp files,restart the computer and run a whole scan with Kaspersky. Trojan.Win32.Fraudpack.amau virus files as following: