Virus Characteristics
FakeAlert-SecurityTool.eg is a Trojan detection that shows false error messages, misleading spyware scan results, and uses aggressive advertising to persuade the user to purchase it.

It would run an exaggerated scan and generate false detection alert messages and warnings. The intention behind all the fake messages is drive users to purchase the advertised product.

Upon execution the Trojan copies itself into the below mentioned location and connects to the IP address 220.164.[Removed] through a remote port 80.
- %Allusersprofile%\Application Data\529C50DB00044D0F0131C6A62830AC72\529C50DB00044D0F0131C6A62830AC72.exe
Also Trojan drops the following files.
- %Allusersprofile%\Application Data\529C50DB00044D0F0131C6A62830AC72\529C50DB00044D0F0131C6A62830AC72
- %UserProfile%\Start Menu\Programs\Smart Fortress 2012\Smart Fortress 2012.lnk
- %UserProfile%\Naveen\Desktop\Smart Fortress 2012.lnk
The following registry keys have been added to the system.
- HKEY_USERS\ S-1-(VARIES)\Software\Microsoft\Windows\CurrentVersion\RunOnce
- HKEY_USERS\ S-1-(VARIES)\Software\Microsoft\Windows\CurrentVersion\Uninstall
- HKEY_USERS\ S-1-(VARIES)\Software\Microsoft\Windows\CurrentVersion\Uninstall\Smart Fortress 2012
The following Values have been added to the system.
- HKEY_USERS\ S-1-(VARIES)\Software\Microsoft\Windows\CurrentVersion\RunOnce\529C50DB00044D0F0131C6A62830AC72 = "%Allusersprofile%\Application Data\529C50DB00044D0F0131C6A62830AC72\529C50DB00044D0F0131C6A62830AC72.exe"
The above mentioned registry ensures that the Trojan registers itself as a run entry with the compromised system and execute upon every reboot.
- HKEY_USERS\ S-1-(VARIES)\Software\Microsoft\Windows\CurrentVersion\Uninstall\Smart Fortress 2012\
DisplayName = "Smart Fortress 2012"
ShortcutPath = ""%Allusersprofile%\Application Data\529C50DB00044D0F0131C6A62830AC72\529C50DB00044D0F0131C6A62830AC72.exe" -u"
UninstallString = ""%Allusersprofile%\Application Data\529C50DB00044D0F0131C6A62830AC72\529C50DB00044D0F0131C6A62830AC72.exe" -u"
DisplayIcon = "%Allusersprofile%\Application Data\529C50DB00044D0F0131C6A62830AC72\529C50DB00044D0F0131C6A62830AC72.exe,0"
- HKEY_USERS\ S-1-(VARIES)\Software\Microsoft\Windows\CurrentVersion\Uninstall\Smart Fortress 2012
The following folders have been added to the system.
- %Allusersprofile% Application Data\529C50DB00044D0F0131C6A62830AC72
- %UserProfile% Start Menu\Programs\Smart Fortress 2012
The Fake Antivirus performs the following behavior.
- It disables the system tools like regedit and also disables the Anti-virus program, etc.
- It closes all running applications and it will not allow the user to open any applications
- It closes an application whenever a user tries to launch it.
- After execution the source Trojan delete itself from the system.
[Notes: C:\Documents and Settings\[User]\Local Settings\Application Data is %Appdata%, C:\Documents and Settings\[User]\Local Settings\Temp is %Temp%,C:\Documents and Settings\[User] is %UserProfile%]