Home Malware Programs Trojans FakeAlert-DZ

FakeAlert-DZ

Posted: October 28, 2009

FakeAlert-DZ is a Trojan that will redirect Internet browser to an unidentified website. Usually a copy of deceitful security program is hosted on the website and tries to drop other malware onto the infected system. FakeAlert-DZ will show a variety of fake alerts about computer security state on a compromised computer. These false warnings will attempt to persuade users to download a rogue security software program.

Aliases

RogueAntiSpyware.SecurityTool Trojan:Win32/Winwebsec (Microsoft) AntiVirus2008 (Symantec)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %CommonAppData%\13110624\13110624.exe
    2 %CommonAppData%\13110624\13110624.glu
    3 %CommonAppData%\13110624\pc13110624cnf
    4 %CommonAppData%\13110624\pc13110624ins
    5 %DesktopDir%\System Security 2009.lnk
    6 %Programs%\System Security\System Security
    7 %Temp%\00325156.cmd

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\13110624HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SystemSecurity2009
Loading...