Threat Search: 

ThreatExpert's Statistics for Trojan.Fakealert [Ikarus]:

Trojan.Fakealert [Ikarus] is also known as:
Threat AliasNumber of Incidents
Mal/Generic-A [Sophos]527
not-a-virus:FraudTool.Win32.WinAntiVirus.jy [Kaspersky Lab]507
Generic PUP.z!ba [McAfee]484
Win-Trojan/FakeAv.163840 [AhnLab]443
Backdoor.Win32.Frauder.lp [Kaspersky Lab]216
Backdoor.Frauder!sd6 [PC Tools]184
Generic.dx [McAfee]159
Trojan.Fakeavalert [Symantec]97
Mal/Padodor-B [Sophos]65
Generic Downloader.x [McAfee]56
Hoax.Win32.Renos.fhv [Kaspersky Lab]56
Trojan.Fakeavalert!sd6 [PC Tools]56
not-a-virus:FraudTool.Win32.AntiVirusPro.ns [Kaspersky Lab]47
Adware.Gen [Symantec]44
TrojanDownloader:Win32/Renos [Microsoft]41
Backdoor.Win32.Frauder.lm [Kaspersky Lab]36
Backdoor.Win32.Frauder.ln [Kaspersky Lab]36
Backdoor.Win32.Frauder.lo [Kaspersky Lab]36
Backdoor.Win32.Frauder.lq [Kaspersky Lab]36
Backdoor.Win32.Frauder.lr [Kaspersky Lab]36
Backdoor.Win32.Frauder.ls [Kaspersky Lab]36
Mal/FakeVir-G [Sophos]30
Troj/FakeAv-XL [Sophos]30
not-a-virus:FraudTool.Win32.WinAntiVirus.iv [Kaspersky Lab]28
Dropper/FakeAv.2510233 [AhnLab]27
Generic FakeAlert.a [McAfee]26
Mal/FakeAV-BG [Sophos]25
Trojan Horse [Symantec]25
not-a-virus:FraudTool.Win32.WinAntiVirus [Ikarus]22
Trojan:Win32/FakeScanti [Microsoft]22
Trojan.Generic [PC Tools]16
Win32.SuspectCrc [Ikarus]12
FakeAlert-KC.b [McAfee]10
Mal/FakeAV-AD [Sophos]10
SecurityToolFraud [Symantec]10
Packed.Win32.Krap.ai [Kaspersky Lab]8
Backdoor.Tidserv [Symantec]7
Trojan.RogueAV.a.gen [PC Tools]7
Mal/TDSS-A [Sophos]6
Trojan:Win32/Alureon.gen!J [Microsoft]6
Generic BackDoor [McAfee]5
Trojan:Win32/Bumat!rts [Microsoft]5
WindowsAntivirusPro [Symantec]5
Win-Trojan/Xema.variant [AhnLab]5
AntiVirusPro [Symantec]4
Backdoor.Win32.Frauder.oc [Kaspersky Lab]4
FakeAlert-GA.dll [McAfee]4
not-a-virus:FraudTool.Win32.SecretService.a [Kaspersky Lab]4
not-a-virus:FraudTool.Win32.WinAntiVirus.ix [Kaspersky Lab]4
not-a-virus:FraudTool.Win32.XLGuarder.bh [Kaspersky Lab]4
Troj/BHO-NG [Sophos]4
Trojan:Win32/Tiebho.A [Microsoft]4
FakeAlert-BO [McAfee]3
Generic PUP.x [McAfee]3
not-a-virus:FraudTool.Win32.WinAntiVirus.kj [Kaspersky Lab]3
Program:Win32/FakeASC [Microsoft]3
Troj/FakeAle-JO [Sophos]3
Trojan.Win32.FakeScanti [Ikarus]3
Backdoor.Win32.Frauder.nb [Kaspersky Lab]2
Rootkit.Win32.TDSS.gen [Kaspersky Lab]2
Trojan.FakeAlert [PC Tools]2
Trojan.Win32.FraudPack.qfl [Kaspersky Lab]2
VirusResponseLab [Symantec]2
AntiVirus2009 [Symantec]1
Backdoor.Win32.TDSS.bni [Kaspersky Lab]1
Downloader [Symantec]1
FakeAlert-AB.dldr [McAfee]1
FakeAlert-AG.gen.a [McAfee]1
FakeAlert-BM [McAfee]1
FakeAlert-EO [McAfee]1
FakeAlert-EQ [McAfee]1
FakeAlert-ET [McAfee]1
FakeAlert-GV [McAfee]1
Generic Dropper.bw [McAfee]1
Generic.dx!cxm [McAfee]1
Mal/EncPk-FX [Sophos]1
Mal/EncPk-HW [Sophos]1
Mal/EncPk-IF, Mal/EncPk-HH [Sophos]1
Mal/EncPk-II [Sophos]1
Mal/EncPk-JD [Sophos]1
Mal/Generic-A, Mal/FakeAV-BG [Sophos]1
not-a-virus:FraudTool.Win32.Delf.f [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.SpywareGuard2008.b [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.VirusProtectPro.an [Kaspersky Lab]1
Packed.Generic.187 [Symantec]1
Program:Win32/FakeWG.A [Microsoft]1
PWCrack-Winspy [McAfee]1
Rootkit.Win32.TDSS.eyj [Kaspersky Lab]1
SpywareGuard2008 [Symantec]1
Troj/FakeAle-KH [Sophos]1
Troj/FakeAV-GL [Sophos]1
Troj/FakeAV-XB [Sophos]1
Troj/TDSS-F [Sophos]1
Troj/Virtum-Gen [Sophos]1
Trojan.Win32.Agent.arbq [Kaspersky Lab]1
Trojan.Win32.Agent.cfcg [Kaspersky Lab]1
Trojan.Win32.FraudPack.acgs [Kaspersky Lab]1
Trojan.Win32.FraudPack.aqn [Kaspersky Lab]1
Trojan.Win32.FraudPack.hyk [Kaspersky Lab]1
Trojan.Win32.Pakes.nne [Kaspersky Lab]1

Trojan.Fakealert [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
Russian Federation47
Ukraine23

Trojan.Fakealert [Ikarus] is known to be created as:
%CommonAppData%\08476530\08476530.exe
%CommonAppData%\16369934\16369934.exe
%CommonAppData%\23974934\23974934.exe
%CommonAppData%\41997131\41997131.exe
%CommonAppData%\47403220\47403220.exe
%CommonAppData%\70340418\70340418.exe
%CommonAppData%\88478641\88478641.exe
%CommonAppData%\93230320\93230320.exe
%CommonAppData%\97689847\97689847.exe
%CommonAppData%\98054834\98054834.exe
%ProgramFiles%\avrlabs\avrlabs.exe
%ProgramFiles%\avrlabs\avrlabswarning.dll
%ProgramFiles%\errorkiller\regcleaner.dll
%ProgramFiles%\esearch.dll
%ProgramFiles%\lpvideoplugin\5378.exe
%ProgramFiles%\msvideoplugin\z218.exe
%ProgramFiles%\windows police pro\winivsetup.exe
%System%\dddesot.dll
%System%\frmwrk32.exe
%System%\iebho.dll
%System%\msxml71.dll
%Temp%\b.exe
%Temp%\svchasts.exe
%Temp%\wndutl32.dll
%Windir%\svchast.exe
%Windir%\svchasts.exe
Notes:
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.