Les informations contenues dans cette rubrique de notre site web sont constamment mises à jour. Afin de vous garantir un contenu le plus actualisé possible, elles sont uniquement diffusées en anglais.

Virus Profile: Generic FakeAlert!htm

Threat Search
Imprimer
   
Virus Profile information details
Risk Assessment: Home Low-Profiled | Corporate Low-Profiled
Date Discovered: 16/03/2009
Date Added: 16/03/2009
Origin: N/A
Length: varies
Type: Trojan
Subtype: Script
DAT Required: 5555
Removal Instructions
   
 
 
   

Description

Overview -
-- Update July 24, 2009 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://www.theregister.co.uk/2009/07/23/eclipse_scareware_scam/

--

This is a detection for a trojan that displays misleading fake alerts to entice the user into buying a product to "repair" malware problems.

Indication of Infection

Presence of downloaded file

Methods of Infection

Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, etc.

   

Virus Characteristics

Overview -
-- Update July 24, 2009 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://www.theregister.co.uk/2009/07/23/eclipse_scareware_scam/

--

This is a detection for HTML files that contains code for performing fake online malware scan.

The following are some websites that host this Trojan:

  • spyware-scannerv3.com
  • thesecureyourpc.com

Once user connects to any of the above websites, it displays fake malware infection alert.

Then it performs fake malware scanning and shows report of infection.

This fake alerts will then lead to download a Rogue Antivirus Software "Personal Antivirus" and saves it as %USERPROFILE%\local settings\temp\setup-{random}.exe.

The downloaded file is detected as FakeAlert-DI.

Un ordinateur infecté ? Obtenez l'aide d'un expert !

McAfee
Service de suppression des virus

Contactez l'un de nos spécialistes en sécurité par téléphone. Regardez votre PC pendant que nous résolvons le problème à distance.

$89.95 (USD)

Publicité