My Bitdefender
  • 0 Shopping Cart

SHARE
THIS ON

Facebook Twitter Google Plus

Trojan.FakeAV.VE

LOW
MEDIUM
45KB

Symptoms

Annoying pop-up windows saying that the computer is infected and requesting to register the program "Antivirus 2010"
The presence of the folder %Programs%\AntivirusPro_2010  

Removal instructions:

Please let BitDefender disinfect your files.

Analyzed By

Ovidiu Visoiu, virus researcher

Technical Description:

This is a downloader of the Antivirus Pro 2010 fake-alert malware which get installed on the system in two steps. First it will try to download  from few locations (randomly named) a file saved as "%user_documents%\Application Data\lizkavd.exe". The new executable will attempt to connect, using a name and a password, to new locations also (randomly named) and download  a password protected archive. This archive actually contains the fakealert malware (Tojan.FakeAV.VH) which will be installed in the %Programs%\AntivirusPro_2010 folder.
When executed, the downloader will copy itself to: 
       %user_documents%\application data\svcst.exe
       %user_documents%\application data\seres.exe, these will be started together and will protect each other from being terminated by the user using two named mutex.   
Also, the above two copies are registered at the system startup:
     [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
         svchost=
%user_documents%\application data\svcst.exe
         mserv= %user_documents%\application data\seres.exe 
It will lower  security settings modifying folowing registry keys:
     [HKCU\Software\Microsoft\Internet Explorer\Download]
        CheckExeSignatures = no
        RunInvalidSignatures = 0x1
     [HKU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
        LowRiskFileTypes =
zip;.rar;.cab;.txt;.exe;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mov;.mp3;.wav
After setting the aboves the malware will try to download another executable from:
        hxxp://ertanue5skayert.com/s1fb0Uv5MS8X[removed]
        hxxp://abumaso3thkamid.com/nQ1Zx0E5X8[removed]  ...
checking when the download is completed by querying  Program Files\AntivirusPro_2010\AntivirusPro_2010.exe