May connect to remote servers and download malicious files onto the infected computer.
May change home page or search settings to display content related to rogue protection or cleaning software.
May display a fake system scan to try and get users to download and purchase rogue protection or cleaning software.
Adds itself to the infected computer's registry so that the infection runs when Windows starts.
How It Infects: Trojan-Downloader.Win32.FraudLoad.vmli has no specific means of infection.
How To Avoid Infection: Do not click any unexpected links in instant messages. Do not download email attachments from unexpected sources. Do not download unknown files or files from unknown sources. If using StopSign, be sure that the On-Access Scan is installed and enabled. Ensure that all updates are installed from Microsoft's Windows Update.
Vulnerable Operating Systems: Windows 95/98/Me/NT/2000/XP