Virus Profile: Generic FakeAlert!9F6E4576

Threat Search
Print
   
Virus Profile information details
Risk Assessment: Home Low-Profiled | Corporate Low-Profiled
Date Discovered: 10/20/2009
Date Added: 10/20/2009
Origin: N/A
Length: 44,544 bytes
Type: Trojan
Subtype: Downloader
DAT Required: 5778
Removal Instructions
   
 
 
   

Description

This detection is for a FakeAlert trojan, that was spammed as a free tool to scan for the "Conficker.B" worm.

Indication of Infection

  • Presence of the files and registry entries mentioned.
  • Increase in bandwidth usage due to additional files being downloaded.

Methods of Infection

Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, etc.

This malware was spammed as a free tool to scan for the "Conficker.B" worm.

Aliases

Packed.Win32.Krap.ah (Kaspersky), Trojan.FakeAV (Symantec), W32/FakeAlert.SYY!tr.dldr (Fortinet)
   

Virus Characteristics

-- Update October 21, 2009 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at: http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=220700200

--

This detection is for a FakeAlert trojan, that was spammed as a free tool to scan for the "Conficker.B" worm.

Upon execution, this malware copies itself to the following locations and launches them.

  • %userprofile%\Application Data\seres.exe
  • %userprofile%\Application Data\svcst.exe

It then downloads a malicious file to the following location

  • %userprofile%\Application Data\lizkavd.exe (detected as FakeAlert-XPSecCenter)

it then pops up a fake message, stating the the system is infected (as shown below)


Upon clicking the message baloon, the "lizkavd.exe" is run, which downloads and installs a fake antivirus program.


The following registry entries are created/modified


HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures"
 Data: 01, 00, 00, 00

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes"
 Data: zip;.rar;.cab;.txt;.exe;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mov;.mp3;.wav

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "mserv"
 Data: %userprofile%\Application Data\seres.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "svchost"
 Data: %userprofile%\Application Data\svcst.exe

   
AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.

Additional Windows ME/XP removal considerations