Submission Summary:

What's been foundSeverity Level
Contains characteristics of a rogue antispyware application that uses aggressive and deceptive advertising along with false reports of exaggerated system security threats to persuade users to download and purchase their product.

 

Technical Details:

 

File System Modifications

#Filename(s)File SizeFile HashAlias
1 %DesktopDir%\Antivirus 2009.lnk 670 bytes MD5: 0xC24EC1BFB13297C89781292CC35E2285
SHA-1: 0x6C5F32ADDB3CAE92906FED44333D8EF5686F899B
(not available)
2 %StartMenu%\Antivirus 2009\Antivirus 2009.lnk 676 bytes MD5: 0x8DB16EA4E759C2F128AA545923D1CF98
SHA-1: 0xE5EA44089F6DBEE89C31BDDA85FCDDBEBA83A96C
(not available)
3 %StartMenu%\Antivirus 2009\Uninstall Antivirus 2009.lnk 698 bytes MD5: 0x4578BEDC2754B587A975818E45A51902
SHA-1: 0x2507F12C366184CF2A6CC3735C6CEFB60A317932
(not available)
4 %System%\ieupdates.exe.tmp 0 bytes MD5: 0xD41D8CD98F00B204E9800998ECF8427E
SHA-1: 0xDA39A3EE5E6B4B0D3255BFEF95601890AFD80709
(not available)
5 [file and pathname of the sample #1] 2,277,376 bytes MD5: 0x73FE2CCB755F2993D3812A76335690B4
SHA-1: 0x495C9FD82D7DD8E1A740BD2B08D6E912FA485F94
HeurEngine.MaliciousPacker [PCTools]
Packed.Generic.187 [Symantec]
Trojan-FakeAV.Win32.XPAntivirus.aae [Kaspersky Lab]
Generic Dropper.bw [McAfee]
Troj/FakeVir-JP [Sophos]
Trojan-FakeAV [Ikarus]
6 %System%\scui.cpl 78,336 bytes MD5: 0xB69DAF8D44CBBB438DD86240C4960D07
SHA-1: 0x8AC658BDB8F999FE81A0182606A12D9C8B7F2D46
RogueAntiSpyware.AntiVirusPro [PCTools]
AntiVirus2009 [Symantec]
Trojan-FakeAV.Win32.XPAntivirus.ty [Kaspersky Lab]
FakeAlert-AB [McAfee]
TROJ_FAKEALER.GV [Trend Micro]
Troj/FakeAle-GZ [Sophos]
Rogue:Win32/FakeXPA [Microsoft]
not-a-virus:FraudTool.Win32.XPAntivirus [Ikarus]
Win-Trojan/Fakealert.78344 [AhnLab]
packed with UPX [Kaspersky Lab]

 

Memory Modifications

Process NameProcess FilenameMain Module Size
[filename of the sample #1][file and pathname of the sample #1]5,455,872 bytes

 

Registry Modifications

 

Other details

Russian Federation

 

 

All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.

The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.

Copyright © 2013 ThreatExpert. All rights reserved.