Home Malware Programs Fake Warning Messages 'Warning! Trojan Found!' Popup

'Warning! Trojan Found!' Popup

Posted: March 30, 2009

'Warning! Trojan Found!' Popup is a fake security alert popup that appears as a misleading security result whenever the rogue anti-spyware program UltraAntivir 2009 completes a scan of a user's computer. Ultra Antivir 2009 is a rogue anti-spyware application that performs fake spyware scans that scare user's into purchasing its full version. The 'Warning! Trojan Found!' Popup message states:

"Warning!Trojan Found!
Threat detected: Trojan
File name: kernel32.exe
Threat name: Trojan-PSW.Win32.Hooker
File at risk of infection: C:\Documents and Settings\…
Total Vulnerabilities: 2
Description: This is a password-stealing Trojan. When activated, it installs itself to the system, copies itself to the Windows or Windows system directory and registers itself in the system registry auto-run section."

Do not click on the 'Remove' button or any link provided by 'Warning!Trojan Found!' Popup. Once you click on the 'Remove' button, you'll be redirected to a rogue website to download and purchase UltraAntivr 2009 or other popular rogue anti-spyware programs.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Ultra Antivir2009.lnk
    2 %UserProfile%\Application Data\Ultra Antivir2009
    3 %UserProfile%\Application Data\Ultra Antivir2009\Instructions.ini
    4 %UserProfile%\Desktop\Ultra Antivir2009.lnk
    5 %UserProfile%\Start Menu\Programs\Ultra Antivir2009.lnk
    6 %UserProfile%\Start Menu\Ultra Antivir2009.lnk
    7 c:\Documents and Settings\All Users\Application Data\7c69f0c
    8 c:\Documents and Settings\All Users\Application Data\7c69f0c\SystemStore
    9 c:\Documents and Settings\All Users\Application Data\7c69f0c\SystemStore\vd952342.bd
    10 c:\Documents and Settings\All Users\Application Data\7c69f0c\UA2009.exe
    11 c:\Documents and Settings\All Users\Application Data\SystemStore
    12 c:\Documents and Settings\All Users\Application Data\SystemStore\uavir.cfg
    13 c:\WINDOWS\$hf_mig$\KB947864-IE7\update\kernel32.tmp
    14 c:\WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\delfile.sys
    15 c:\WINDOWS\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\CLSV.dll
    16 c:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\energy.exe
    17 c:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\CLSV.dll
    18 c:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\ANTIGEN.sys
    19 c:\WINDOWS\ime\exec.dll
    20 c:\WINDOWS\ime\snl2w.drv
    21 c:\WINDOWS\Installer\$PatchCache$\Managed\D6461317C3DC4F04799BDCE9E42626FE\2.0.50727\ANTIGEN.sys
    22 c:\WINDOWS\Installer\$PatchCache$\Managed\D6461317C3DC4F04799BDCE9E42626FE\2.0.50727\energy.exe
    23 c:\WINDOWS\ServicePackFiles\i386\ppal.dll
    24 c:\WINDOWS\ServicePackFiles\i386\ppal.tmp
    25 c:\WINDOWS\ServicePackFiles\i386\SICKBOY.exe
    26 c:\WINDOWS\ServicePackFiles\i386\snl2w.drv
    27 c:\WINDOWS\std.drv
    28 c:\WINDOWS\system32\tjd.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "4800156103"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Ultra Antivir2009"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}HKEY_CLASSES_ROOT\CLSID\{425882B0-B0BF-11CE-B59F-00AA006CB37D}HKEY_CLASSES_ROOT\UA2009.DocHostUIHandler
Loading...