Content
FakeAlert-DI
- Type
- Trojan
- SubType
- Win32
- Discovery Date
- 05/28/2009
- Length
- varies
- Minimum DAT
- 5629 (05/28/2009)
- Updated DAT
- 5761 (10/04/2009)
- Minimum Engine
- 5.2.00
- Description Added
- 05/28/2009
- Description Modified
- 09/29/2009 10:06 PM (PT)
Tab Navigation
Characteristics
----Updated September 30, 2009-----
Rogue Antivirus Softaware "Personal Antivirus" has been repackaged and now called "Alpha Antivirus".
The following websites host this new family:
- mycompinfo17.com
- internetantivirusproscanner.com
- mycomputeronlinescan11.com
- internetsecurityscan.com
The following files are added upon execution:
- %ALLUSERSPROFILE%\start menu\AlphaAV\Alpha Antivirus.lnk
- %ALLUSERSPROFILE%\start menu\AlphaAV\uninstall.lnk
- %COMMONPROGRAMFILES%\uninstall\AlphaAV\uninstall.lnk
- %PROGRAMFILES%\AlphaAV\AlphaAV.exe - detected as FakeAlert-DI
- %USERPROFILE%\desktop\Alpha Antivirus.lnk
- %WINDIR%\system32\msnaoladdon.dll - detected as FakeAlert-EQ
The following registry is added:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\currentversion\Run\
AlphaAV= c:\program files\AlphaAV\AlphaAV.exe
HKEY_CLASSES_ROOT\CLSID\{a77d3539-581d-450c-9e44-a84c415a6172}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a77d3539-581d-450c-9e44-a84c415a6172}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a77d3539-581d-450c-9e44-a84c415a6172}
Then it launches the Alpha Antivirus to show fake malware scan reports.

Other pop-up messages:



---------------
This Trojan is usually downloaded from malicious websites performing fake online scan. The following are some website that hosts this Trojan:
- spyware-scannerv3.com
- thesecureyourpc.com
This can also be downloaded by Generic FakeAlert!htm and saves it as %USERPROFILE%\local settings\temp\setup-{random}.exe
Upon execution, it downloads Rogue Antispyware Softaware "Personal Antivirus" from the above website and executes it.
The following files are added:
- %ALLUSERSPROFILE%\start menu\personalav\personal antivirus.lnk
- %ALLUSERSPROFILE%\start menu\personalav\uninstall.lnk
- %COMMONPROGRAMFILES%\uninstall\personalav\uninstall.lnk
- %PROGRAMFILES%\personalav\pav.exe - detected as FakeAlert-DI
- %USERPROFILE%\desktop\personal antivirus.lnk
- %WINDIR%\system32\msxmlm.dll - detected as FakeAlert-EQ
Note:%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following registry is added:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\currentversion\run\
personalav = c:\program files\personalav\pav.exe
The trojan shows the following fake warnings in bubble warning.

Then it launches the Personal Antivirus to show fake malware scan reports.

Then it asks the infected user to register and purchase the product to remove the infection.

Symptoms
Presence of the mentioned files and registry keys
Method of Infection
Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, etc.
Removal
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Variants
Variants
N/A
All Information
Overview -
----Updated September 30, 2009-----
Personal Antivirus has been repackaged as Alpha Antivirus.
-------------
This is a detection for a trojan that displays misleading fake alerts to entice the user into buying a product to "repair" malware problems.
Characteristics
Characteristics -
----Updated September 30, 2009-----
Rogue Antivirus Softaware "Personal Antivirus" has been repackaged and now called "Alpha Antivirus".
The following websites host this new family:
- mycompinfo17.com
- internetantivirusproscanner.com
- mycomputeronlinescan11.com
- internetsecurityscan.com
The following files are added upon execution:
- %ALLUSERSPROFILE%\start menu\AlphaAV\Alpha Antivirus.lnk
- %ALLUSERSPROFILE%\start menu\AlphaAV\uninstall.lnk
- %COMMONPROGRAMFILES%\uninstall\AlphaAV\uninstall.lnk
- %PROGRAMFILES%\AlphaAV\AlphaAV.exe - detected as FakeAlert-DI
- %USERPROFILE%\desktop\Alpha Antivirus.lnk
- %WINDIR%\system32\msnaoladdon.dll - detected as FakeAlert-EQ
The following registry is added:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\currentversion\Run\
AlphaAV= c:\program files\AlphaAV\AlphaAV.exe
HKEY_CLASSES_ROOT\CLSID\{a77d3539-581d-450c-9e44-a84c415a6172}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a77d3539-581d-450c-9e44-a84c415a6172}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a77d3539-581d-450c-9e44-a84c415a6172}
Then it launches the Alpha Antivirus to show fake malware scan reports.

Other pop-up messages:



---------------
This Trojan is usually downloaded from malicious websites performing fake online scan. The following are some website that hosts this Trojan:
- spyware-scannerv3.com
- thesecureyourpc.com
This can also be downloaded by Generic FakeAlert!htm and saves it as %USERPROFILE%\local settings\temp\setup-{random}.exe
Upon execution, it downloads Rogue Antispyware Softaware "Personal Antivirus" from the above website and executes it.
The following files are added:
- %ALLUSERSPROFILE%\start menu\personalav\personal antivirus.lnk
- %ALLUSERSPROFILE%\start menu\personalav\uninstall.lnk
- %COMMONPROGRAMFILES%\uninstall\personalav\uninstall.lnk
- %PROGRAMFILES%\personalav\pav.exe - detected as FakeAlert-DI
- %USERPROFILE%\desktop\personal antivirus.lnk
- %WINDIR%\system32\msxmlm.dll - detected as FakeAlert-EQ
Note:%WinDir% = \WINDOWS (Windows 9x/ME/XP/Vista), \WINNT (Windows NT/2000)
%SystemDir% = \WINDOWS\SYSTEM (Windows 98/ME), \WINDOWS\SYSTEM32 (Windows XP/Vista), \WINNT\SYSTEM32 (Windows NT/2000)
%ProgramFiles% = \Program Files
The following registry is added:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\currentversion\run\
personalav = c:\program files\personalav\pav.exe
The trojan shows the following fake warnings in bubble warning.

Then it launches the Personal Antivirus to show fake malware scan reports.

Then it asks the infected user to register and purchase the product to remove the infection.

Symptoms
Symptoms -
Presence of the mentioned files and registry keys
Method of Infection
Method of Infection -
Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, etc.
Removal -
Removal -
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A