'Warning! Trojan Found!' Popup
'Warning! Trojan Found!' Popup is a fake security alert popup that appears as a misleading security result whenever the rogue anti-spyware program UltraAntivir 2009 completes a scan of a user's computer. Ultra Antivir 2009 is a rogue anti-spyware application that performs fake spyware scans that scare user's into purchasing its full version. The 'Warning! Trojan Found!' Popup message states:
"Warning!Trojan Found!
Threat detected: Trojan
File name: kernel32.exe
Threat name: Trojan-PSW.Win32.Hooker
File at risk of infection: C:\Documents and Settings\…
Total Vulnerabilities: 2
Description: This is a password-stealing Trojan. When activated, it installs itself to the system, copies itself to the Windows or Windows system directory and registers itself in the system registry auto-run section."
Do not click on the 'Remove' button or any link provided by 'Warning!Trojan Found!' Popup. Once you click on the 'Remove' button, you'll be redirected to a rogue website to download and purchase UltraAntivr 2009 or other popular rogue anti-spyware programs.
File System Modifications
- The following files were created in the system:
# File Name 1 %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Ultra Antivir2009.lnk 2 %UserProfile%\Application Data\Ultra Antivir2009 3 %UserProfile%\Application Data\Ultra Antivir2009\Instructions.ini 4 %UserProfile%\Desktop\Ultra Antivir2009.lnk 5 %UserProfile%\Start Menu\Programs\Ultra Antivir2009.lnk 6 %UserProfile%\Start Menu\Ultra Antivir2009.lnk 7 c:\Documents and Settings\All Users\Application Data\7c69f0c 8 c:\Documents and Settings\All Users\Application Data\7c69f0c\SystemStore 9 c:\Documents and Settings\All Users\Application Data\7c69f0c\SystemStore\vd952342.bd 10 c:\Documents and Settings\All Users\Application Data\7c69f0c\UA2009.exe 11 c:\Documents and Settings\All Users\Application Data\SystemStore 12 c:\Documents and Settings\All Users\Application Data\SystemStore\uavir.cfg 13 c:\WINDOWS\$hf_mig$\KB947864-IE7\update\kernel32.tmp 14 c:\WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\delfile.sys 15 c:\WINDOWS\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\CLSV.dll 16 c:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\energy.exe 17 c:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\CLSV.dll 18 c:\WINDOWS\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\ANTIGEN.sys 19 c:\WINDOWS\ime\exec.dll 20 c:\WINDOWS\ime\snl2w.drv 21 c:\WINDOWS\Installer\$PatchCache$\Managed\D6461317C3DC4F04799BDCE9E42626FE\2.0.50727\ANTIGEN.sys 22 c:\WINDOWS\Installer\$PatchCache$\Managed\D6461317C3DC4F04799BDCE9E42626FE\2.0.50727\energy.exe 23 c:\WINDOWS\ServicePackFiles\i386\ppal.dll 24 c:\WINDOWS\ServicePackFiles\i386\ppal.tmp 25 c:\WINDOWS\ServicePackFiles\i386\SICKBOY.exe 26 c:\WINDOWS\ServicePackFiles\i386\snl2w.drv 27 c:\WINDOWS\std.drv 28 c:\WINDOWS\system32\tjd.exe
Registry Modifications
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "4800156103"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Ultra Antivir2009"HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}HKEY_CLASSES_ROOT\CLSID\{425882B0-B0BF-11CE-B59F-00AA006CB37D}HKEY_CLASSES_ROOT\UA2009.DocHostUIHandler
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.