Content
FakeAlert-R
- Type
- Trojan
- SubType
- Win32
- Discovery Date
- 09/12/2007
- Length
- Minimum DAT
- 5118 (09/12/2007)
- Updated DAT
- 5715 (08/20/2009)
- Minimum Engine
- 4.4.00
- Description Added
- 09/12/2007
- Description Modified
- 09/13/2007 3:19 AM (PT)
Tab Navigation
Characteristics
This trojan is composed of many components, all detected as FakeAlert-R(.dll) trojans:
- %Temp%\frmwrk.exe: main part. This one downloads the other components.
- %Sysdir%\bho.dll: installed as a BHO and detected as FakeAlert-R.dll
- %Sysdir%\center1.exe
- %Sysdir%\center2.exe
- %Sysdir%\center.exe
- %Sysdir%\win321.exe
- %Sysdir%\win32.exe
Upon execution the trojan shows a popup balloon with a display message like the one shown in the picture below:

Then the other files are downloaded from downloadfilesldr.com and www.spywaresoftstop.com.
A few seconds later, the desktop wallpaper is replaced by a black one with a red rectangle at the bottom right, displaying the following fake message:

And the following windows will regularly pop up:
- A fake Dr Watson message:

- A fake Windows Security Center warning refering to the Trojan.Spambot.PBFRV2:

Moreover the following HTML page may appear when starting Internet Explorer:

All messages try to lure the user into clicking on a link that delivers the advertised antispyware product.
The trojan creates the following registry entry to activate itself on system startup:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Framework"
Data: C:\DOCUME~1\{username}\LOCALS~1\Temp\frmwrk.exe
The following registry keys are also created, in order to install the FakeAlert-R.dll as a BHO, to disable the Task Manager, to remove the Active Desktop item from the Settings menu, to disable Active Desktop and to remove the Web tab and disable all options on the Background tab of Display in Control Panel:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallpaper"
Data: 01, 00, 00, 00 - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoActiveDesktopChanges"
Data: 01, 00, 00, 00 - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoSetActiveDesktop"
Data: 01, 00, 00, 00 - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr"
Data: 01, 00, 00, 00 - HKEY_CLASSES_ROOT\BhoNew.BhoApp "(Default)"
Data: BhoApp Class - HKEY_CLASSES_ROOT\BhoNew.BhoApp.1 "(Default)"
Data: BhoApp Class - HKEY_CLASSES_ROOT\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} "(Default)"
Data: BhoApp Class - HKEY_CLASSES_ROOT\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91} "(Default)"
Data: _IBhoAppEvents - HKEY_CLASSES_ROOT\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5} "(Default)"
Data: IBhoApp - HKEY_CLASSES_ROOT\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0 "(Default)"
Data: BhoNew 1.0 Type Library
Symptoms
- Fake system alerts warning of active malicious program as mentioned in the Characteristics section.
- Presence of aforementioned files.
Method of Infection
Trojans do not self-replicate. They spread manually, often under the premise that the executable is something beneficial. Trojans may also be received as a result of poor security practices, or un-patched machines and vulnerable systems. Distribution channels include IRC, peer-to-peer networks, email, newsgroups postings, etc
Removal
AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.
Variants
Variants
N/A
All Information
Overview -
Similar to other malwares of this family, FakeAlert-R shows a fake warning message, alarming the users that their machine is infected or at risk. The intention behind all the fake messages is drive users to download the advertised antispyware product.
Characteristics
Characteristics -
This trojan is composed of many components, all detected as FakeAlert-R(.dll) trojans:
- %Temp%\frmwrk.exe: main part. This one downloads the other components.
- %Sysdir%\bho.dll: installed as a BHO and detected as FakeAlert-R.dll
- %Sysdir%\center1.exe
- %Sysdir%\center2.exe
- %Sysdir%\center.exe
- %Sysdir%\win321.exe
- %Sysdir%\win32.exe
Upon execution the trojan shows a popup balloon with a display message like the one shown in the picture below:

Then the other files are downloaded from downloadfilesldr.com and www.spywaresoftstop.com.
A few seconds later, the desktop wallpaper is replaced by a black one with a red rectangle at the bottom right, displaying the following fake message:

And the following windows will regularly pop up:
- A fake Dr Watson message:

- A fake Windows Security Center warning refering to the Trojan.Spambot.PBFRV2:

Moreover the following HTML page may appear when starting Internet Explorer:

All messages try to lure the user into clicking on a link that delivers the advertised antispyware product.
The trojan creates the following registry entry to activate itself on system startup:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Framework"
Data: C:\DOCUME~1\{username}\LOCALS~1\Temp\frmwrk.exe
The following registry keys are also created, in order to install the FakeAlert-R.dll as a BHO, to disable the Task Manager, to remove the Active Desktop item from the Settings menu, to disable Active Desktop and to remove the Web tab and disable all options on the Background tab of Display in Control Panel:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallpaper"
Data: 01, 00, 00, 00 - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoActiveDesktopChanges"
Data: 01, 00, 00, 00 - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoSetActiveDesktop"
Data: 01, 00, 00, 00 - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr"
Data: 01, 00, 00, 00 - HKEY_CLASSES_ROOT\BhoNew.BhoApp "(Default)"
Data: BhoApp Class - HKEY_CLASSES_ROOT\BhoNew.BhoApp.1 "(Default)"
Data: BhoApp Class - HKEY_CLASSES_ROOT\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} "(Default)"
Data: BhoApp Class - HKEY_CLASSES_ROOT\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91} "(Default)"
Data: _IBhoAppEvents - HKEY_CLASSES_ROOT\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5} "(Default)"
Data: IBhoApp - HKEY_CLASSES_ROOT\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0 "(Default)"
Data: BhoNew 1.0 Type Library
Symptoms
Symptoms -
- Fake system alerts warning of active malicious program as mentioned in the Characteristics section.
- Presence of aforementioned files.
Method of Infection
Method of Infection -
Trojans do not self-replicate. They spread manually, often under the premise that the executable is something beneficial. Trojans may also be received as a result of poor security practices, or un-patched machines and vulnerable systems. Distribution channels include IRC, peer-to-peer networks, email, newsgroups postings, etc
Removal -
Removal -
AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A