Threat Search: 

ThreatExpert's Statistics for FakeAlert-EL [McAfee]:

FakeAlert-EL [McAfee] is also known as:
Threat AliasNumber of Incidents
Trojan Horse [Symantec]25
Trojan-Downloader.Win32.FraudLoad [Ikarus]22
Troj/FakeVir-NU [Sophos]20
Trojan-Downloader.Win32.FraudLoad.ezj [Kaspersky Lab]20
Win-Trojan/Downloader.60416.AB [AhnLab]20
Mal/EncPk-HW [Sophos]15
TrojanDownloader:Win32/Renos.GW [Microsoft]10
Trojan.Win32.FraudPack [Ikarus]7
Generic Dropper.bw [McAfee]4
Mal/FakeAV-AY [Sophos]4
Mal/Renos-J [Sophos]4
Packed.Generic.187 [Symantec]4
TROJ_FRAUDLO.PEK [Trend Micro]4
Trojan-Downloader.Win32.Renos [Ikarus]4
Win-Trojan/Xema.variant [AhnLab]4
Downloader [Symantec]3
Mal/EncPk-JD [Sophos]3
Mal/Generic-A [Sophos]3
Trojan.Renos [Ikarus]3
Trojan.Win32.FraudPack.pre [Kaspersky Lab]3
Win32.SuspectCrc [Ikarus]3
Mal/EncPk-HW, Mal/EncPk-JD [Sophos]2
Win-Trojan/Agent.158208.BO [AhnLab]2
Win-Trojan/Zbot.160768 [AhnLab]2
Downloader.Generic [PC Tools]1
Dropper/FakeAlert.187908 [AhnLab]1
Dropper/Fakealert.247300 [AhnLab]1
Mal/EncPk-JD, Mal/EncPk-HW, Mal/Renos-J [Sophos]1
Mal/Renos-J, Mal/EncPk-JH [Sophos]1
SpywareStrike [Symantec]1
Troj/Agent-KNV [Sophos]1
TROJ_FAKEAL.CI [Trend Micro]1
Trojan.Fakeavalert [Symantec]1
Trojan.Win32.Agent2.cgmf [Kaspersky Lab]1
Trojan.Win32.FraudPack.pip [Kaspersky Lab]1
Trojan.Win32.FraudPack.pkb [Kaspersky Lab]1
Trojan.Win32.FraudPack.pkc [Kaspersky Lab]1
Trojan.Win32.FraudPack.pkh [Kaspersky Lab]1
Trojan.Win32.FraudPack.pmw [Kaspersky Lab]1
Trojan.Win32.FraudPack.pov [Kaspersky Lab]1
Trojan.Win32.FraudPack.pqo [Kaspersky Lab]1
Trojan-Downloader.Win32.Agent.cinm [Kaspersky Lab]1
Trojan-Downloader.Win32.Agent.ciyv [Kaspersky Lab]1
Trojan-Downloader.Win32.FraudLoad.emq [Kaspersky Lab]1
Trojan-Downloader.Win32.FraudLoad.evr [Kaspersky Lab]1
Trojan-Downloader.Win32.FraudLoad.evt [Kaspersky Lab]1
Trojan-Downloader.Win32.FraudLoad.evx [Kaspersky Lab]1
Trojan-Downloader.Win32.FraudLoad.exe [Kaspersky Lab]1
Trojan-Downloader.Win32.FraudLoad.eza [Kaspersky Lab]1
Trojan-Downloader.Win32.FraudLoad.ezn [Kaspersky Lab]1
Trojan-Downloader.Win32.FraudLoad.wcyi [Kaspersky Lab]1
TrojanDownloader:Win32/Renos.DY [Microsoft]1
TrojanDownloader:Win32/Renos.EI [Microsoft]1
TrojanDownloader:Win32/Renos.JA [Microsoft]1
Win-Trojan/Fakeav.182276 [AhnLab]1
Win-Trojan/Fraudload.124420.C [AhnLab]1
Win-Trojan/Fraudload.154624 [AhnLab]1
Win-Trojan/Fraudload.175746 [AhnLab]1
Win-Trojan/Fraudload.179204 [AhnLab]1
Win-Trojan/Fraudpack.132608.B [AhnLab]1
Win-Trojan/Renos.124416 [AhnLab]1
Win-Trojan/Renos.178692 [AhnLab]1
Win-Trojan/Renos.48128 [AhnLab]1
Win-Trojan/Renos.84480.B [AhnLab]1

FakeAlert-EL [McAfee] has the following possible country of origin:
OriginNumber of Incidents
Russian Federation6

FakeAlert-EL [McAfee] is known to be created as:
%Temp%\a.exe
%Temp%\b.exe
%Temp%\c.exe
%Temp%\d.exe
%Temp%\e.exe
%Temp%\f.exe
%Temp%\g.exe
%Temp%\h.exe
%Temp%\i.exe
%Temp%\kafan virlist 20090715\090714-5-2.exe
%Temp%\kafan virlist 20090715\090714-7-10.exe
%Temp%\kafan virlist 20090715\090714-7-7.exe
%Temp%\kafan virlist 20090715\090714-7-8.exe
%Temp%\msa.exe
%Temp%\msb.exe
%Windir%\install.exe
%Windir%\msa.exe
Notes:
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.