Virus: TR/Fakealert.QE Date discovered: 16/10/2008 Type: Trojan In the wild: Yes Reported Infections: Low to medium Distribution Potential: Low Damage Potential: Low to medium Static file: No IVDF version: 7.00.07.46 - Thursday, October 16, 2008
General Method of propagation: • No own spreading routine Aliases: • Symantec: AntiVirus2009 • Kaspersky: not-a-virus:FraudTool.Win32.XPSecurityCenter.az • F-Secure: not-a-virus:FraudTool.Win32.XPSecurityCenter.az • Panda: Adware/XPAntiSpyware2009 • Grisoft: Downloader.Small.ELY Platforms / OS: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads files • Downloads malicious files Right after execution the following information is displayed: Files The following files are created: – Non malicious files: • %PROGRAM FILES% \XP_AntiSpyware\Uninstall.exe; %PROGRAM FILES%\XP_AntiSpyware\htmlayout.dll; %PROGRAM FILES%\XP_AntiSpyware\pthreadVC2.dll; %PROGRAM FILES%\XP_AntiSpyware\Microsoft.VC80.CRT\msvcp80.dll; %PROGRAM FILES%\XP_AntiSpyware\Microsoft.VC80.CRT\msvcm80.dll; %PROGRAM FILES%\XP_AntiSpyware\Microsoft.VC80.CRT\msvcr80.dll; %PROGRAM FILES%\XP_AntiSpyware\data\daily.cvd; %HOME%\Start Menu\Programs\XP_AntiSpyware\XP_AntiSpyware.lnk; %HOME%\Desktop\XP_AntiSpyware.lnk; %HOME%\Start Menu\Programs\XP_AntiSpyware\XP_AntiSpyware.lnk; %HOME%\Start Menu\Programs\XP_AntiSpyware\Uninstall.lnk – Temporary files that might be deleted afterwards: • %TEMPDIR% \prm2 • %TEMPDIR% \prm3 – %PROGRAM FILES% \XP_AntiSpyware\AVEngn.dll Further investigation pointed out that this file is malware, too. Detected as: TR/Fakealert.QF – %TEMPDIR% \Binaries1.cab2 – %TEMPDIR% \Binaries2.cab3 – %TEMPDIR% \Binaries3.cab4 It tries to download some files: – The location is the following: • http://www.xpas2009.com/**********/Binaries1.cab It is saved on the local hard drive under: %temporary internet files% \Content.IE5\%eight-digit random character string% \Binaries1[1].cab – The location is the following: • http://www.xpas2009.com/**********/Binaries2.cab It is saved on the local hard drive under: %temporary internet files% \Content.IE5\%eight-digit random character string% \Binaries2[1].cab – The location is the following: • http://www.xpas2009.com/**********/Binaries3.cab It is saved on the local hard drive under: %temporary internet files% \Content.IE5\%eight-digit random character string% \Binaries3[1].cab It tries to executes the following files: – Filename: • %PROGRAM FILES% \XP_AntiSpyware\XP_AntiSpyware.exe Furthermore it contains malicious code. Detected as: TR/Drop.Delf.Crypt.G.24 – Filename: • %PROGRAM FILES% \XP_AntiSpyware\wscui.cpl Furthermore it contains malicious code. Detected as: TR/Fakealert.QE File details Programming language: The malware program was written in MS Visual C++. Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Andreas Feuerstein on Tuesday, October 21, 2008 Description updated by Andreas Feuerstein on Tuesday, October 21, 2008
Back
.
.
.
.