Home Malware Programs Trojans FakeAlert-AVPSec.e

FakeAlert-AVPSec.e

Posted: May 14, 2010

FakeAlert-AVPSec.e is a malicious Trojan that poses a severe threat to computer security. FakeAlert-AVPSec.e silently installs itself on the victims computer and runs a fabricated virus scan that claims the PC is infected with malware. FakeAlert-AVPSec.e also gives fake alert warnings which prompt users to purchase the registered version of a rogue program.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 c:\Documents and Settings\%user%\Application Data\Microsoft\Internet Explorer\Quick Launch\My Security Engine.lnk
    2 c:\Documents and Settings\%user%\Application Data\My Security Engine
    3 c:\Documents and Settings\%user%\Application Data\My Security Engine\Instructions.ini
    4 c:\Documents and Settings\%user%\Desktop\My Security Engine.lnk
    5 c:\Documents and Settings\%user%\Local Settings\Temp\packupdate_build107_328.exe
    6 c:\Documents and Settings\%user%\Start Menu\My Security Engine.lnk
    7 c:\Documents and Settings\%user%\Start Menu\Programs\My Security Engine.lnk
    8 c:\Documents and Settings\All Users\Application Data\b45b499
    9 c:\Documents and Settings\All Users\Application Data\b45b499\3411.mof
    10 c:\Documents and Settings\All Users\Application Data\b45b499\BackUp\Adobe Reader Speed Launch.lnk
    11 c:\Documents and Settings\All Users\Application Data\b45b499\MSb45b.exe
    12 c:\Documents and Settings\All Users\Application Data\b45b499\MSE.ico
    13 c:\Documents and Settings\All Users\Application Data\b45b499\MSESys\vd952342.bd
    14 c:\Documents and Settings\All Users\Application Data\MSTLDEE
    15 c:\Documents and Settings\All Users\Application Data\MSTLDEE\MSHIBFFJWSE.cfg

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\3 HKEY_CLASSES_ROOT\MSb45b.DocHostUIHandlerHKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes [URL] Data: http://find[removed].com/?&uid=328&q={searchTerms}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer [IIL] Data: 00, 00, 00, 00HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer [PRS] Data: http://127.0.0.1:27777/?inj=%ORIGINAL%HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer [ltHI] Data: 00, 00, 00, 00HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer [ltTST] Data: A5, 81, 00, 00HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation [MSCompatibilityMode] Data: 00, 00, 00, 00HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download [RunInvalidSignatures] Data: 01, 00, 00, 00HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run [My Security Engine] Data: MSb45b.exe /s /dHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnceHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FWCFGHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\Current Version\Image File ExecutionHKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes [URLs] Data: http://find[removed].com/?&uid=328&q={searchTerms}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF} [(Default)] Data: Implements DocHostUIHandlerHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\Firewall Policy\StandardProfile\AuthorizedApplications\List [MSb45b.exe] Data: MSb45b.exeHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\Firewall Policy\StandardProfile\AuthorizedApplications\List [MSb45b.ex] Data: MSb45b.exe
Loading...