Virus Profile: FakeAlert-IE

Threat Search
Print
   
Virus Profile information details
Risk Assessment: Home Low | Corporate Low
Date Discovered: 9/10/2009
Date Added: 9/10/2009
Origin: N/A
Length: N/A
Type: Trojan
Subtype: Win32
DAT Required: 5737
Removal Instructions
   
 
 
   

Description

This is a detection for a Trojan that displays misleading fake alerts to entice the user into buying a product to "repair" malware problems. This trojan may masquerade its malicious behavior, and victims are likely to have installed it thinking it is an innocent screensaver program.

Indication of Infection

  • Presence of the files mentioned above
  • Presence of the registry entry mentioned above
  • Modification of Hosts file
  • Dispaly of Pop ups and Alerts
  • Fake system scan

Methods of Infection

Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, etc.

Aliases

Trojan.Fakeavalert(Symantec), Trojan:Win32/FakeSpypro(Microsoft), Win32/Adware.SpywareProtect2009(NOD32)
   

Virus Characteristics

Upon execution FakeAlert-IE creates a file vqsosysguard.exe under ubkecs folder in Program files.The file name may vary on every execution but ends with xxxxsysguard.exe(As wcalsysguard.exe etc).

The following files were added by FakeAlert-IE:

C:\Program Files\ubkecs\vqsosysguard.exe
%System%\iehelper.dll

Where %System% = c:\WINDOWS\system32

The following registry entries were made by FakeAlert-IE:

HKEY_CURRENT_USER\Software\AvScan "aazalirt" = "1"
HKEY_CURRENT_USER\Software\AvScan "dkekkrkska" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "system tool"
C:\Program Files\ubkecs\vqsosysguard.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "system tool"
C:\Program Files\ubkecs\vqsosysguard.exe

The Trojan also modifies the hosts file at %System%\ drivers\etc\hosts .Often this is used to redirect the victims browsing to a specific malicious website and prevent users from downloading updates.The modified hosts file will contain a list of URLs redirected to IP 91.2x2.1xx.2x1

The modified host file will be as below:

91.2x2.1xx.2x1 axxrerxmovxr.mixrosxft.com
91.2x2.1xx.2x1 axxrerexover.com
91.2x2.1xx.2x1 www.axxreremxxer.com     

Trojan then installs Fake Antivirus and performs system scan showing presence of malwares in the system as shown below:

Then gives a popup asking for removal of threats on purchase of the product as below:

Also popups alert messages as shown below alerting the user to prevent attacks from the malwares and provides description on the attack.

On opening the browser after the installation of FakeAlert-IE it redirects the browser to pornography websites such as

http://www.pxxno.org  
http://www.adxlx.com  
http://www.vixgrx.com  

 

   
AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.

Additional Windows ME/XP removal considerations