Home Malware Programs Trojans VirusResponse Alert

VirusResponse Alert

Posted: September 22, 2008

"VirusResponse Alert" popup is a fake security warning message that is designed to promote the VirusResponse Lab 2009 rogue anti-spyware program. If "yes" is clicked on the "VirusResponse Alert" popup. it may redirect you to a malicious website that promotes the VirusResponse Lab 2009 program where it entices you to purchase it.

The "VirusResponse Alert" popup message reads like the text below.

"VirusResponse Alert
INFILTRATION ALERT
Your computer is being attacked from Internet. It could be a password-stealing attack, a trojan-dropper and so on.
DETAILS
Attack from: 47.242.140.139, port 9771
Attacked port: 27890
Threat: Trojan.Tibs.E
Do you want VirusResponse Lab 2009 to block this attack?"

"VirusResponse Alert" popup and VirusResponse Lab 2009 may be difficult to manually remove. It is suggested that you use a reputable spyware scan tool to detect any infection that may be causing the "VirusResponse Alert" popup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 c:\Documents and Settings\Adminstrator\Desktop\VirusResponse Lab 2009.lnk
    2 c:\Documents and Settings\Adminstrator\Start Menu\Programs\VirusResponse Lab 2009
    3 c:\Documents and Settings\Adminstrator\Start Menu\VirusResponse Lab 2009.lnk
    4 c:\Program Files\VirusResponseLab2009
    5 c:\Program Files\VirusResponseLab2009\AVLWarning.dll
    6 c:\Program Files\VirusResponseLab2009\uninst.exe
    7 c:\Program Files\VirusResponseLab2009\VirusResponseLab2009.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\VirusResponseLab2009HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersionHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\VirusResponseLab2009HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A21C8D81-A9C7-46c6-A488-2A32FA0DAEB6}HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\AVLWarning.WarningBHOHKEY_CLASSES_ROOT\AVLWarning.WarningBHO.1HKEY_CLASSES_ROOT\CLSID\{A21C8D81-A9C7-46c6-A488-2A32FA0DAEB6}HKEY_CLASSES_ROOT\CLSID\{F5734812-E6A1-8833-ECA9-949B5B8A88BF}HKEY_CLASSES_ROOT\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}HKEY_CLASSES_ROOT\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}HKEY_CLASSES_ROOT\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}
Loading...