Virus Characteristics
-- Update October 22, 2009 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://www.theregister.co.uk/2009/10/21/kanye_west_scareware
--
This is a detection for a trojan that displays misleading fake alerts to entice the user into buying a product to "repair spyware or malware problems". This trojan may masquerade its malicious behavior, and victims are likely to have installed it thinking it is an innocent screensaver program.
When executed, the following registry entries are created:
- HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes
- HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes
- HKEY_USERS\S-1-5-19\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes
- HKEY_USERS\S-1-5-19_Classes\Software\Microsoft\Internet Explorer\SearchScopes
- HKEY_USERS\S-1-5-20\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes
- HKEY_USERS\S-1-5-21-854245398-796845957-1417001333-500_Classes\Software\Microsoft\Internet Explorer\SearchScopes
- HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes
- HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
The following data/value pair is added for running itself:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Smart Virus Eliminator"
Data: "C:\Documents and Settings\All Users\Application Data\bd3bf\SM7a4.exe" /s /d
The following files are added:
- %SysRoot%\Documents and Settings\[Current User]\Local Settings\Temp\asp2009.exe
- %SysRoot%\Documents and Settings\[Current User]\Local Settings\Temp\SMVE.ico
- %SysRoot%\Documents and Settings\Current User]\Local Settings\Temp\SMVESys\vd952342.bd
- %SysRoot%\Documents and Settings\[Current User]\Start Menu\Smart Virus Eliminator.lnk
- %SysRoot%\Documents and Settings\[Current User]Start Menu\Programs\Smart Virus Eliminator.lnk
- %SysRoot%\Documents and Settings\All Users\Application Data\bd3bf\SM7a4.exe
- %SysRoot%\Documents and Settings\All Users\Application Data\SMVESys\smve.cfg
- %SysRoot%\Documents and Settings\[Current User]\Desktop\Smart Virus Eliminator.lnk
These files are detected as FakeAlert-WPS.
Connections may also be made with the following domains:
- freeav[removed].com
- prest[removed].cn
- gurus[removed].com
The malware will run a fake scan of the host, and intermittantely pop up fake infection warnings. These warnings may appear like the below images:
A fake update warning:
A false warning for remote data leaking:

A false bot infection:
A false Trojan infection:
