Threat Database Trojans FakeAlert-KS.gen.e

FakeAlert-KS.gen.e

By JubileeX in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 5
First Seen: August 29, 2011
Last Seen: November 5, 2022
OS(es) Affected: Windows

FakeAlert-KS.gen.e is a hazardous Trojan infection that enables Internet attackers to get remote access to the compromised computer system. FakeAlert-KS.gen.e is able to steal your sensitive details and transmit them to remote attackers. FakeAlert-KS.gen.e will make changes to the system settings in a try to damage your PC. FakeAlert-KS.gen.e also download and install malicious files by connecting to a remote server secretly. You should uninstall FakeAlert-KS.gen.e as soon as possible to keep your computer safe.

File System Details

FakeAlert-KS.gen.e may create the following file(s):
# File Name Detections
1. %System%\smss32.exe
2. %System%\wsnpoem\audio.dll
3. %System%\41.exe
4. %System%\winlogon32.exe
5. %DesktopDir%\Internet Security 2010.lnk
6. c:\14.tmp
7. %Windir%\Temp\Temporary Internet
8. %AppData%\avdrn.dat
9. c:\12.tmp
10. %Windir%\Temp\Temporary Internet Files\Content.IE5\MDE3KROJ\in[1].txt
11. %System%\lowsec\user.ds
12. %Profiles%\LocalService\Application Data\mvhgkr.dat
13. %Temp%\dfgdgdfgrgdgfdrdfs.tmp
14. %Windir%\Temp\hsf78w3uhduf8w.tmp
15. Files\Content.IE5\499JDBB1\regiondata[2].aspx

Registry Details

FakeAlert-KS.gen.e may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop NoChangingWallpaper = 0x00000001
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5BF49A2-94F1-42BD-F434-3604812C807D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5BF49A2-94F1-42BD-F434-3604812C807D} (Default) = "%System%\x5i4y0v55p.dll" ThreadingModel = "Apartment"
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT
HKEY_USERS\.DEFAULT\Software\Microsoft\Protected Storage System Provider
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run reader_s = "%System%\reader_s.exe" smss32.exe = "%System%\smss32.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5BF49A2-94F1-42BD-F434-3604812C807D}\InProcServer32 (Default) = "%System%\x5i4y0v55p.dll" ThreadingModel = "Apartment"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer NoSetActiveDesktop = 0x00000001 NoActiveDesktopChanges = 0x00000001
HKEY_LOCAL_MACHINE\SOFTWARE\AGProtect
HKEY_CURRENT_USER\Software\IS2010
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5BF49A2-94F1-42BD-F434-3604812C807D}\InProcServer32

Trending

Most Viewed

Loading...