Les informations contenues dans cette rubrique de notre site web sont constamment mises à jour. Afin de vous garantir un contenu le plus actualisé possible, elles sont uniquement diffusées en anglais.

Virus Profile: FakeAlert-JT

Threat Search
Imprimer
   
Virus Profile information details
Risk Assessment: Home Low-Profiled | Corporate Low-Profiled
Date Discovered: 21/10/2009
Date Added: 21/10/2009
Origin: N/A
Length: N/A
Type: Trojan
Subtype: Win32
DAT Required: 5779
Removal Instructions
   
 
 
   

Description

-- Update October 22, 2009 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://www.theregister.co.uk/2009/10/21/kanye_west_scareware

--

This is a detection for a trojan that displays misleading fake alerts to entice the user into buying a product to "repair" malware problems. This trojan may masquerade its malicious behavior, and victims are likely to have installed it thinking it is an innocent screensaver program.

Indication of Infection

  • Presence of the aforementioned files and registry entries.
  • Unexpected network connections to the aforementioned domains.

Methods of Infection

Trojans do not self-replicate. They spread manually, often under the premise that the executable is something beneficial. Trojans may also be received as a result of poor security practices, or un-patched machines and vulnerable systems. Distribution channels include IRC, peer-to-peer networks, email, newsgroups postings, etc

   

Virus Characteristics

-- Update October 22, 2009 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://www.theregister.co.uk/2009/10/21/kanye_west_scareware

--

This is a detection for a trojan that displays misleading fake alerts to entice the user into buying a product to "repair spyware or malware problems". This trojan may masquerade its malicious behavior, and victims are likely to have installed it thinking it is an innocent screensaver program.

 

When executed, the following registry entries are created:

  • HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes
  • HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes
  • HKEY_USERS\S-1-5-19\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes
  • HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Internet Explorer\SearchScopes
  • HKEY_USERS\S-1-5-20\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes
  • HKEY_USERS\S-1-5-21-854245398-796845957-1417001333-500_Classes\Software\Microsoft\Internet Explorer\SearchScopes
  • HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes
  • HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}

The following data/value pair is added for running itself:

  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Smart Virus Eliminator"
    Data: "C:\Documents and Settings\All Users\Application Data\bd3bf\SM7a4.exe" /s /d

The following files are added:

  • %SysRoot%\Documents and Settings\[Current User]\Local Settings\Temp\asp2009.exe
  • %SysRoot%\Documents and Settings\[Current User]\Local Settings\Temp\SMVE.ico
  • %SysRoot%\Documents and Settings\Current User]\Local Settings\Temp\SMVESys\vd952342.bd
  • %SysRoot%\Documents and Settings\[Current User]\Start Menu\Smart Virus Eliminator.lnk
  • %SysRoot%\Documents and Settings\[Current User]Start Menu\Programs\Smart Virus Eliminator.lnk
  • %SysRoot%\Documents and Settings\All Users\Application Data\bd3bf\SM7a4.exe
  • %SysRoot%\Documents and Settings\All Users\Application Data\SMVESys\smve.cfg
  • %SysRoot%\Documents and Settings\[Current User]\Desktop\Smart Virus Eliminator.lnk

These files are detected as FakeAlert-WPS.

Connections may also be made with the following domains:

  • freeav[removed].com
  • prest[removed].cn
  • gurus[removed].com

The malware will run a fake scan of the host, and intermittantely pop up fake infection warnings. These warnings may appear like the below images:

A fake update warning:

A false warning for remote data leaking:

A false bot infection:

 

A false Trojan infection:

   

All Users:
Use current engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

   

Un ordinateur infecté ? Obtenez l'aide d'un expert !

McAfee
Service de suppression des virus

Contactez l'un de nos spécialistes en sécurité par téléphone. Regardez votre PC pendant que nous résolvons le problème à distance.

$89.95 (USD)

Publicité