Home Malware Programs Fake Warning Messages Warning! Spambot Detected!

Warning! Spambot Detected!

Posted: October 14, 2010

Warning! Spambot Detected! Screenshot 1'Warning! Spambot Detected!' is a fake popup window. If 'Warning! Spambot Detected!' appears on your screen your computer is most likely infected with rogue security software. The aim of this popup is to decieve computer users to purchase the rogue security it promotes. 'Warning! Spambot Detected!' should be removed immediately using an apdated malware remover.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 c:\Documents and Settings\All Users\Application Data\ae01cc\
    2 c:\Documents and Settings\All Users\Application Data\ae01cc\61.mof
    3 c:\Documents and Settings\All Users\Application Data\ae01cc\ae01cc42668ec8a22e4d0493aabb97d8.ocx
    4 c:\Documents and Settings\All Users\Application Data\ae01cc\mozcrt19.dll
    5 c:\Documents and Settings\All Users\Application Data\ae01cc\Quarantine Items\
    6 c:\Documents and Settings\All Users\Application Data\ae01cc\SMae0_2129.exe
    7 c:\Documents and Settings\All Users\Application Data\ae01cc\SME.ico
    8 c:\Documents and Settings\All Users\Application Data\ae01cc\SMESys
    9 c:\Documents and Settings\All Users\Application Data\ae01cc\sqlite3.dll
    10 c:\Documents and Settings\All Users\Application Data\SMIFGKMPDQE
    11 c:\Documents and Settings\All Users\Application Data\SMIFGKMPDQE\SMTKWKE.cfg

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Smart Engine.lnk%UserProfile%\Application Data\Smart Engine%UserProfile%\Application Data\Smart Engine\cookies.sqlite%UserProfile%\Desktop\Smart Engine.lnk%UserProfile%\Recent\ANTIGEN.dll%UserProfile%\Recent\ANTIGEN.drv%UserProfile%\Recent\CLSV.exe%UserProfile%\Recent\CLSV.sys%UserProfile%\Recent\DBOLE.drv%UserProfile%\Recent\PE.dll%UserProfile%\Recent\cid.tmp%UserProfile%\Recent\delfile.sys%UserProfile%\Recent\eb.sys%UserProfile%\Recent\energy.exe%UserProfile%\Recent\exec.exe%UserProfile%\Recent\fan.drv%UserProfile%\Recent\kernel32.dll%UserProfile%\Recent\pal.exe%UserProfile%\Recent\ppal.drv%UserProfile%\Recent\tempdoc.tmp%UserProfile%\Start Menu\Programs\Smart Engine.lnk%UserProfile%\Start Menu\Smart Engine.lnk
Loading...