・実行時、FakeAlert-CN.gen.aaはリモートポート80を介して208.110.[削除]に接続し、悪質なファイルをダウンロードします。
・実行のたびに以下のような偽のウイルス対策製品の名前を表示します。
- XP Anti-Spyware
- XP Total Security 2011
- XP Home Security..
・実行時、以下のファイルシステムにをドロップ(作成)します。
- %AppData%\2s22w7m80644je3p6opmh763e52iwdktya6q0s7jq0h784
- %Temp%\2s22w7m80644je3p6opmh763e52iwdktya6q0s7jq0h784
- %UserProfile%\Local Settings\Application Data\2s22w7m80644je3p6opmh763e52iwdktya6q0s7jq0h784
- %UserProfile%\Local Settings\Application Data\jpj.exe
- %UserProfile%\Templates\2s22w7m80644je3p6opmh763e52iwdktya6q0s7jq0h784
・以下の偽のダイアログ、アイコン、警告、ポップアップなどを表示します。








・さらに、エラーを取り除くため、アプリケーションのフルライセンスを購入するよう促します。


・以下のレジストリキーが追加されます。
- HKEY_CURRENT_USER\S-1-[不定]\Software\Classes\.exe\DefaultIcon
- HKEY_CURRENT_USER\S-1-[不定]\Software\Classes\.exe\shell\open\command
- HKEY_CURRENT_USER\S-1-[不定]\Software\Classes\.exe\shell\runas\command
- HKEY_CURRENT_USER\S-1-[不定]\Software\Classes\exefile\DefaultIcon
- HKEY_CURRENT_USER\S-1-[不定]\Software\Classes\exefile\shell\open\command
- HKEY_CURRENT_USER\S-1-[不定]\Software\Classes\exefile\shell\runas\command
- HKEY_CURRENT_USER\S-1-[不定]_Classes\.exe\DefaultIcon
- HKEY_CURRENT_USER\S-1-[不定]_Classes\.exe\shell\open\command
- HKEY_CURRENT_USER\S-1-[不定]_Classes\.exe\shell\runas\command
- HKEY_CURRENT_USER\S-1-[不定]_Classes\exefile\DefaultIcon
- HKEY_CURRENT_USER\S-1-[不定]_Classes\exefile\shell\open\command
- HKEY_CURRENT_USER\S-1-[不定]_Classes\exefile\shell\runas\command
・以下のレジストリ値が追加されます。
- HKEY_CURRENT_USER\S-1-[不定]\Software\Microsoft\Windows\
Identity = 0xBB9461F6
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\
DisableNotifications = 0x1
DoNotAllowExceptions= 0x0
EnableFirewall = 0x0
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\
DisableNotifications = 0x1
DoNotAllowExceptions = 0x0
- HKEY_CURRENT_USER\S-1-[不定]\Software\Classes\.exe\shell\open\command\
= ""%UserProfile%\Desktop\yir.exe" -a "%1" %*"
IsolatedCommand = ""%1" %*"
- HKEY_CURRENT_USER\S-1-[不定]\Software\Classes\.exe\shell\runas\command\
= ""%1" %*"
IsolatedCommand = ""%1" %*"
- HKEY_CURRENT_USER\S-1-[不定]\Software\Classes\.exe\DefaultIcon\
= "%1"
- HKEY_CURRENT_USER\S-1-[不定]\Software\Classes\.exe\
= "exefile"
Content Type= "application/x-msdownload"
- HKEY_CURRENT_USER\S-1-[不定]\Software\Classes\exefile\shell\open\command\
= ""%UserProfile%\Desktop\yir.exe" -a "%1" %*"
IsolatedCommand= ""%1" %*"
- HKEY_CURRENT_USER\S-1-[不定]\Software\Classes\exefile\shell\runas\command\
= ""%1" %*"
IsolatedCommand= ""%1" %*"
- HKEY_CURRENT_USER\S-1-[不定]\Software\Classes\exefile\DefaultIcon\
= "%1"
- HKEY_CURRENT_USER\S-1-[不定]\Software\Classes\exefile\
= "Application"
Content Type= "application/x-msdownload"
- HKEY_CURRENT_USER\S-1-[不定]_Classes\.exe\shell\open\command\
= ""%UserProfile%\Desktop\yir.exe" -a "%1" %*"
IsolatedCommand = ""%1" %*"
- HKEY_CURRENT_USER\S-1-[不定]_Classes\.exe\shell\runas\command\
= ""%1" %*"
IsolatedCommand= ""%1" %*"
- HKEY_CURRENT_USER\S-1-[不定]_Classes\.exe\DefaultIcon\
= "%1"
- HKEY_CURRENT_USER\S-1-[不定]_Classes\.exe\
= "exefile"
Content Type = "application/x-msdownload"
- HKEY_CURRENT_USER\S-1-[不定]_Classes\exefile\shell\open\command\
= ""%UserProfile%\Desktop\yir.exe" -a "%1" %*"
IsolatedCommand = ""%1" %*"
- HKEY_CURRENT_USER\S-1-[不定]_Classes\exefile\shell\runas\command\
= ""%1" %*"
IsolatedCommand = ""%1" %*"
- HKEY_CURRENT_USER\S-1-[不定]_Classes\exefile\DefaultIcon\
= "%1"
- HKEY_CURRENT_USER\S-1-[不定]_Classes\exefile\
= "Application"
Content Type = "application/x-msdownload"
・以下のレジストリ値が改変されます。
- HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center\
FirewallOverride = 0x1
- HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\
= ""%UserProfile%\Desktop\yir.exe" -a "%ProgramFiles%\Mozilla Firefox\firefox.exe""
- HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\
= ""%UserProfile%\Desktop\yir.exe" -a "%ProgramFiles%\Mozilla Firefox\firefox.exe" -safe-mode"
- HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\
= ""%UserProfile%\Desktop\yir.exe" -a "%ProgramFiles%\Internet Explorer\iexplore.exe""
- HKEY_CURRENT_USER\S-1-[不定]\Software\Clients\StartMenuInternet\
= "FIREFOX.EXE"
- HKEY_CURRENT_USER\S-1-[不定]\Software\Clients\StartMenuInternet\
= "IEXPLORE.EXE"
・以下のウイルス対策製品のプロセスと文字列を検索し、強制終了します。
- AVG Technologies
- ALWIL Software
- Malwarebytes
- Lavasoft
- MpCmdRun.exe
- MsMpEng.exe
- NisSrv.exe
- msseces.exe
注: [%UserProfile% - C:\Documents and Settings\[ユーザ名],
%ProgramFiles% - C:\Program Files,
%AppData% - C:\Documents and Settings\[ユーザ名]\Application Data,
%Temp% - C:\Documents and Settings\[ユーザ名]\Local Settings\Temp]