Threat Search: 

ThreatExpert's Statistics for FakeAlert-XPSecCenter [McAfee]:

FakeAlert-XPSecCenter [McAfee] is also known as:
Threat AliasNumber of Incidents
FakeAlert-XPSecurityCenter [McAfee]14,092
XPSecurityCenter [Symantec]3,126
not-a-virus:FraudTool.Win32.XPSecurityCenter.b [Kaspersky Lab]2,372
New Malware.aj [McAfee]1,774
TROJ_FAKEAV.DAM [Trend Micro]1,710
Mal/Packer [Sophos]878
Packed/Upack [PC Tools]333
not-a-virus:FraudTool.Win32.XPSecurityCenter.o [Kaspersky Lab]288
TrojanDownloader:Win32/FakeRean [Microsoft]176
TROJ_FAKEAV.RIT [Trend Micro]169
Trojan-Downloader.Win32.FakeRean [Ikarus]169
not-a-virus:FraudTool.Win32.XPSecurityCenter.t [Kaspersky Lab]156
RogueAntiSpyware.XPSecurityCenter!mem [PC Tools]152
Packed.Generic.233 [Symantec]139
Mal/EncPk-EQ [Sophos]131
Troj/FakeAV-AA [Sophos]115
not-a-virus:FraudTool.Win32.XPSecurityCenter.k [Kaspersky Lab]114
Trojan.Win32.FakePowav [Ikarus]110
TrojanDownloader:Win32/FakeRean.gen!C [Microsoft]107
Mal/EncPk-IF [Sophos]104
Trojan.Virantix.C [Symantec]97
Trojan-Downloader.Win32.FraudLoad.vdjr [Kaspersky Lab]81
Trojan.Win32.FraudPack.rcj [Kaspersky Lab]64
Trojan-Downloader.Win32.FraudLoad.fkv [Kaspersky Lab]62
Mal/Generic-A [Sophos]45
TROJ_FAKEAV.AC [Trend Micro]43
Downloader.MisleadApp [Symantec]32
not-a-virus:FraudTool.Win32.XPSecurityCenter.p [Kaspersky Lab]25
Mal/EncPk-BW [Sophos]24
Trojan.Virantix!sd6 [PC Tools]19
Virus.Win32.Virut.au [Ikarus]14
Generic.Win32.Malware.XPSecurityCenter [Ikarus]13
TROJ_FAKEALE.SMB [Trend Micro]12
Trojan.Win32.FakeAV [Ikarus]9
Trojan-Dropper.Win32.FrauDrop.hh [Kaspersky Lab]9
Win-Trojan/Antiav.189791 [AhnLab]9
HeurEngine.MaliciousPacker [PC Tools]8
Win-Trojan/Fakeav.190993.B [AhnLab]7
Packed.Win32.Krap.ad [Kaspersky Lab]6
Win-Trojan/Fakeav.Gen [AhnLab]5
Mal/EncPk-HJ [Sophos]4
Packed.Win32.Krap [Ikarus]4
Trojan.Win32.Agent [Ikarus]4
Trojan.Win32.Pakes.lnh [Kaspersky Lab]4
Trojan-Downloader.MisleadApp!sd6 [PC Tools]4
TrojanDownloader:Win32/Fakeinit [Microsoft]4
XLGuarder [Symantec]4
AntiVirus2009 [Symantec]3
Mal/EncPk-KP [Sophos]3
Troj/FakeAle-JI [Sophos]3
Trojan.Crypt [Ikarus]3
Trojan.Win32.FraudPack.gtt [Kaspersky Lab]3
Trojan:Win32/FakeRean [Microsoft]3
Trojan-Downloader.Win32.Renos [Ikarus]3
Trojan-Spy.Win32.Banker.anv [Ikarus]3
AntiVirus2008 [Symantec]2
Generic FakeAlert.a [McAfee]2
Mal/EncPk-LT, Mal/EncPk-IF, Mal/EncPk-KP [Sophos]2
Mal/Fakecor-B, Mal/Behav-314, Mal/EncPk-IF [Sophos]2
Mal/FakeDouf-A, Mal/Bredo-C [Sophos]2
Mal/Packer, Mal/EncPk-BW [Sophos]2
not-a-virus:FraudTool.Win32.XPAntiSpyware2009.i [Kaspersky Lab]2
not-a-virus:FraudTool.Win32.XPSecurityCenter.c [Kaspersky Lab]2
Packed.Generic.258 [Symantec]2
Packed.Win32.Krap.ah [Kaspersky Lab]2
RogueAntiSpyware.AntiVirusPro [PC Tools]2
Suspicious.MH690 [Symantec]2
Troj/FakeVir-DT [Sophos]2
Trojan.Win32.Agent.azpp [Kaspersky Lab]2
Trojan.Zlob [Symantec]2
Trojan.Zlob!sd6 [PC Tools]2
Trojan-Clicker.Osewlone [PC Tools]2
Trojan-Clicker.Win32.Vesloruki [Ikarus]2
Trojan-Clicker.Win32.Vesloruki.cgp [Kaspersky Lab]2
Trojan-Downloader.Win32.FraudLoad.fwi [Kaspersky Lab]2
TrojanDownloader:Win32/Renos [Microsoft]2
TrojanDropper:Win32/Olmarik.A [Microsoft]2
Win-Trojan/Fraudload.76892 [AhnLab]2
Win-Trojan/Vesloruki.233472.EQ [AhnLab]2
Backdoor.UltimateDefender [PC Tools]1
Backdoor.Win32.UltimateDefender.yx [Kaspersky Lab]1
Hoax.Win32.Renos.vapv [Kaspersky Lab]1
Mal/EncPk-IF, Mal/EncPk-KP [Sophos]1
Mal/EncPk-MP, Mal/EncPk-IF [Sophos]1
Mal/EncPk-MP, Mal/EncPk-LT, Mal/FakeAV-BT, Mal/FakeAV-BX, Mal/EncPk-IF [Sophos]1
Mal/Fakecor-B, Mal/Behav-314 [Sophos]1
Mal/FakeDouf-A [Sophos]1
Mal/Generic-A, Mal/Fakecor-B, Mal/Behav-314, Mal/EncPk-IF [Sophos]1
not-a-virus:FraudTool.Win32.AntiVirusPro.fc [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.AntiVirusPro.ff [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.AntiVirusPro.fh [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.AntiVirusPro.k [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.AntiVirusPro.u [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.XPAntiSpyware2009.h [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.XPSecurityCenter.az [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.XPSecurityCenter.ba [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.XPSecurityCenter.d [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.XPSecurityCenter.n [Kaspersky Lab]1
Packed.Win32.Krap.t [Kaspersky Lab]1
Packed.Win32.Krap.x [Kaspersky Lab]1

FakeAlert-XPSecCenter [McAfee] has the following possible countries of origin:
OriginNumber of Incidents
Ukraine19,845
Russian Federation166

FakeAlert-XPSecCenter [McAfee] is known to be created as:
%AppData%\lizkavd.exe
%AppData%\seres.exe
%AppData%\svcst.exe
%ProgramFiles%\antiviruspro_2010\antiviruspro_2010.exe
%ProgramFiles%\antiviruspro2009\uninstall.exe
%ProgramFiles%\xp_antispyware\uninstall.exe
%System%\frmwrk32.exe
%System%\sdra64.exe
%System%\wisdstr.exe
%Temp%\avto1.exe
%Temp%\avto3.exe
%Temp%\avto4.exe
%Temp%\install.exe
%Temp%\msupd_2.exe
%Temp%\q1.exe
%Temp%\teste2_p.exe
%Temp%\teste3_p.exe
%Temp%\teste4_p.exe
%Temp%\wini10491.exe
%Temp%\winivstr.exe
%Temp%\wisdstr.exe
%Temp%\xpsecuritycenter.exe
%Windir%\amoumain.exe
%Windir%\ctfmon.exe
%Windir%\servicelayer.exe
%Windir%\svc.exe
%Windir%\svw.exe
%Windir%\vlc.exe
%Windir%\wdmon.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.