Virus Characteristics
-------------Updated on June 7, 2012-----------------------------------
- Comodo - UnclassifiedMalware
- Fortinet - W32/FakeAV.OZ!tr
- NOD32 - Win32/Adware.HDDRescue.AB
- Symantec - Suspicious.Cloud.5
FakeAlert-SysDef.ae is a Trojan detection, which shows S.M.A.R.T. Repair of fake computer optimization and entice the users into buying a product to repair computer problems.
Upon execution the Trojan displays the following window


Upon execution the Trojan tries to connect to the following URL wha[Removed]ima.com through the port 80.
When executed the Trojan copies itself into the following location.
- %AllUsersprofile%\Application Data\$5q_QsVfM.nc=lIK.exe
After execution, the Trojan deletes self from the compromised system.
The Trojan drops the files into the following location.
- %AllUsersprofile%\Application Data\-9H'&ra6@
- %AllUsersprofile%\Application Data\-9H'&ra6@r
- %AllUsersprofile%\Application Data\9H'&ra6@
- %AllUsersprofile%\Application Data\9H'&ra6@.exe
The Trojan drops the following shortcut files which triggers a Trojan file
- %Userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Data_Recovery.lnk
- %Userprofile%\Desktop\Data_Recovery.lnk
- %Userprofile%\Start Menu\Programs\Data Recovery\Data Recovery.lnk
- %Userprofile%\Start Menu\Programs\Data Recovery\Uninstall Data Recovery.lnk
The following registry entries have been added to the system.
- HKEY_CURRENT_USER\S-1-(Varies)\Software\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnonBadCertRecving: 0x00000000
- HKEY_CURRENT_USER\S-1-(Varies)\Software\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\LowRiskFileTypes: ".zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.scr;"
- HKEY_CURRENT_USER\S-1-(Varies)\Software\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\SaveZoneInformation: 0x00000001
Below mentioned registry ensures that, the Trojan registers itself with the compromised system and execute itself upon every boot.
- HKEY_CURRENT_USER\S-1-(VARIES)\Software\Microsoft\GDIPlus\FontCachePath: "%Userprofile%\Local Settings\Application Data"
The following registry keys have been added to the system.
- HKEY_CURRENT_USER\S-1-(Varies)\Software\Microsoft\Internet Explorer\Download
- HKEY_CURRENT_USER\S-1-(Varies)\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
- HKEY_CURRENT_USER\S-1-(Varies)\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments
- HKEY_CURRENT_USER\S-1-(VARIES)\Software\Microsoft\GDIPlus
Note: [%Userprofile%C:\Documents and Settings\Administrator],[ %Allusersprofile%C:\Documents and Settings\All Users]