Home Malware Programs Trojans Generic FakeAlert.ama

Generic FakeAlert.ama

Posted: March 7, 2011

Far more than just one individual type of infection, Generic FakeAlert.ama is a group of several related Trojans with similar characteristics. Generic FakeAlert.ama-infected computers will experience heavy security vulnerabilities and be afflicted with other kinds of malware that the Trojan downloadvertisement and installs on the system. Any attempts to remove the malware without removing Generic FakeAlert.ama will usually result in Generic FakeAlert.ama re-doing its work, forcing you to start again. This Trojan has also been linked to rogue anti-virus applications, and users should be cautious about alert messages and unusual OS behavior when trying to delete Generic FakeAlert.ama.

The Trojan and the Bad Doctor

As a Trojan connected to the VirusDoctor rogue security program, Generic FakeAlert.ama may be acquired from VirusDoctor-related websites and other malicious sites and file sources. Generic FakeAlert.ama may use misleading desktop alerts and other methods to drop VirusDoctor or other rogue security programs on your computer. Thereafter, these rogue security applications will send you horrifying system alerts and offer system scans that show an amazing number of infections - but all this provided information is fake, and only useful in the sense that it can scare you into giving away your credit card number to criminals.

Other potential threats linked to Generic FakeAlert.ama extend to the following:

  • Disrupted security programs. Rogue security programs and their related Trojans like Generic FakeAlert.ama are often programmed to stop popular anti-malware scanners from working. The relevant scanner will most often be crashed with an accompanying fake error, such as threats of a keylogger or other infection.
  • Altered system settings. Generic FakeAlert.ama may do this to lower security to enable malware installation or to allow for other malicious activities. Proxy server settings are often enabled to let the Trojan or related malware hijack your web browser and force it to go to a dangerous website.
  • Many Trojans have backdoor-based functions; these functions let remote attackers control or damage your computer. Control over your own PC is essentially forfeited to the attacker until you remove Generic FakeAlert.ama and other malware and then close the corresponding security hole.
  • Generic FakeAlert.ama may also create fake alerts and system error pop-ups by itself, without requiring the assistance of a rogue anti-spyware product. This makes it even more difficult to tell what's actually wrong with your computer, can trick you into installing other malware and may even obscure real system messages.
How to Keep Generic FakeAlert.ama from Infecting Your Computer

Since Generic FakeAlert.ama emerged as an identified PC threat early March of 2011, updates to your security programs are needed to let scanners identify the Trojan and do their work. Avoid visiting dangerous websites, especially ones related to rogue security products like VirusDoctor. Never run an .exe file if you're uncertain of the origin or safety of the file, and try to notice when an executable has been mislabeled with another file type tag.

Removing Generic FakeAlert.ama and related malware once you've got the infection will require good anti-malware programs or an expert who can locate all relevant files and registry entries with no false positives or vague guesses. It's strongly recommended that you use a well-known and well-reviewed anti-malware scanner, since attempting to delete Generic FakeAlert.ama with a rogue anti-malware product posing as a security scanner is a complete waste of your time.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ALLUSERSPROFILE%\Application Data\hGnChMl06300\hGnChMl06300
    2 %ALLUSERSPROFILE%\Application Data\hGnChMl06300\hGnChMl06300.exe
    3 %PROGRAM_FILES%\Generic FakeAlert.ama.
    4 %TEMP%\a1A3C.tmp
    5 %TEMP%\a5D69.tmp
    6 %TEMP%\fBiBcGa06300
    7 c:\Documents and Settings\All Users\Start Menu\Generic FakeAlert.ama\ c:\Documents and Settings\All Users\Generic FakeAlert.ama\ and

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING\NEXTID = 8194HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING\{92780B25-18CC-41C8-B9BE-3C9C571A8263} = 8193HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\HGNCHML06300 = %ALLUSERSPROFILE%\Application Data\hGnChMl06300\hGnChMl06300.exeHKEY_LOCAL_MACHINE\Software\Generic FakeAlert.ama
Loading...