Content

FakeAlert-R

Type
Trojan
SubType
Win32
Discovery Date
09/12/2007
Length
Minimum DAT
5118 (09/12/2007)
Updated DAT
5715 (08/20/2009)
Minimum Engine
4.4.00
Description Added
09/12/2007
Description Modified
09/13/2007 3:19 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This trojan is composed of many components, all detected as FakeAlert-R(.dll) trojans:

  • %Temp%\frmwrk.exe: main part. This one downloads the other components.
  • %Sysdir%\bho.dll: installed as a BHO and detected as FakeAlert-R.dll
  • %Sysdir%\center1.exe
  • %Sysdir%\center2.exe
  • %Sysdir%\center.exe
  • %Sysdir%\win321.exe
  • %Sysdir%\win32.exe

Upon execution the trojan shows a popup balloon with a display message like the one shown in the picture below:

Then the other files are downloaded from downloadfilesldr.com and www.spywaresoftstop.com.

A few seconds later, the desktop wallpaper is replaced by a black one with a red rectangle at the bottom right, displaying the following fake message:

And the following windows will regularly pop up:

  • A fake Dr Watson message:

 

  • A fake Windows Security Center warning refering to the Trojan.Spambot.PBFRV2:

 

Moreover the following HTML page may appear when starting Internet Explorer:

 

All messages try to lure the user into clicking on a link that delivers the advertised antispyware product.

 

The trojan creates the following registry entry to activate itself on system startup:

  •  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Framework"
     Data: C:\DOCUME~1\{username}\LOCALS~1\Temp\frmwrk.exe

The following registry keys are also created, in order to install the FakeAlert-R.dll as a BHO, to disable the Task Manager, to remove the Active Desktop item from the Settings menu, to disable Active Desktop and to remove the Web tab and disable all options on the Background tab of Display in Control Panel:

  •  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallpaper"
      Data: 01, 00, 00, 00
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoActiveDesktopChanges"
      Data: 01, 00, 00, 00
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoSetActiveDesktop"
      Data: 01, 00, 00, 00
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr"
      Data: 01, 00, 00, 00
  • HKEY_CLASSES_ROOT\BhoNew.BhoApp "(Default)"
      Data: BhoApp Class
  • HKEY_CLASSES_ROOT\BhoNew.BhoApp.1 "(Default)"
      Data: BhoApp Class
  • HKEY_CLASSES_ROOT\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} "(Default)"
      Data: BhoApp Class
  • HKEY_CLASSES_ROOT\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91} "(Default)"
      Data: _IBhoAppEvents
  • HKEY_CLASSES_ROOT\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5} "(Default)"
      Data: IBhoApp
  • HKEY_CLASSES_ROOT\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0 "(Default)"
      Data: BhoNew 1.0 Type Library

Symptoms

  • Fake system alerts warning of active malicious program as mentioned in the Characteristics section.
  • Presence of aforementioned files.

Method of Infection

Trojans do not self-replicate. They spread manually, often under the premise that the executable is something beneficial. Trojans may also be received as a result of poor security practices, or un-patched machines and vulnerable systems. Distribution channels include IRC, peer-to-peer networks, email, newsgroups postings, etc

Removal

AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

Similar to other malwares of this family, FakeAlert-R shows a fake warning message, alarming the users that their machine is infected or at risk. The intention behind all the fake messages is drive users to download the advertised antispyware product.

Characteristics

Characteristics -

This trojan is composed of many components, all detected as FakeAlert-R(.dll) trojans:

  • %Temp%\frmwrk.exe: main part. This one downloads the other components.
  • %Sysdir%\bho.dll: installed as a BHO and detected as FakeAlert-R.dll
  • %Sysdir%\center1.exe
  • %Sysdir%\center2.exe
  • %Sysdir%\center.exe
  • %Sysdir%\win321.exe
  • %Sysdir%\win32.exe

Upon execution the trojan shows a popup balloon with a display message like the one shown in the picture below:

Then the other files are downloaded from downloadfilesldr.com and www.spywaresoftstop.com.

A few seconds later, the desktop wallpaper is replaced by a black one with a red rectangle at the bottom right, displaying the following fake message:

And the following windows will regularly pop up:

  • A fake Dr Watson message:

 

  • A fake Windows Security Center warning refering to the Trojan.Spambot.PBFRV2:

 

Moreover the following HTML page may appear when starting Internet Explorer:

 

All messages try to lure the user into clicking on a link that delivers the advertised antispyware product.

 

The trojan creates the following registry entry to activate itself on system startup:

  •  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Framework"
     Data: C:\DOCUME~1\{username}\LOCALS~1\Temp\frmwrk.exe

The following registry keys are also created, in order to install the FakeAlert-R.dll as a BHO, to disable the Task Manager, to remove the Active Desktop item from the Settings menu, to disable Active Desktop and to remove the Web tab and disable all options on the Background tab of Display in Control Panel:

  •  HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallpaper"
      Data: 01, 00, 00, 00
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoActiveDesktopChanges"
      Data: 01, 00, 00, 00
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoSetActiveDesktop"
      Data: 01, 00, 00, 00
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr"
      Data: 01, 00, 00, 00
  • HKEY_CLASSES_ROOT\BhoNew.BhoApp "(Default)"
      Data: BhoApp Class
  • HKEY_CLASSES_ROOT\BhoNew.BhoApp.1 "(Default)"
      Data: BhoApp Class
  • HKEY_CLASSES_ROOT\CLSID\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} "(Default)"
      Data: BhoApp Class
  • HKEY_CLASSES_ROOT\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91} "(Default)"
      Data: _IBhoAppEvents
  • HKEY_CLASSES_ROOT\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5} "(Default)"
      Data: IBhoApp
  • HKEY_CLASSES_ROOT\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0 "(Default)"
      Data: BhoNew 1.0 Type Library

Symptoms

Symptoms -

  • Fake system alerts warning of active malicious program as mentioned in the Characteristics section.
  • Presence of aforementioned files.

Method of Infection

Method of Infection -

Trojans do not self-replicate. They spread manually, often under the premise that the executable is something beneficial. Trojans may also be received as a result of poor security practices, or un-patched machines and vulnerable systems. Distribution channels include IRC, peer-to-peer networks, email, newsgroups postings, etc

Removal -

Removal -

AVERT recommends to always use latest DATs and engine. This threat will be cleaned if you have this combination.

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A