Threat Database Fake Error Messages HalfLemon Infiltration Alert

HalfLemon Infiltration Alert

HalfLemon Infiltration Alert is a fake warning notification created and launched by the rogue anti-spyware application known as Windows Antivirus Pro, in order to scare the user into thinking that the computer has been infected. The HalfLemon Infiltration Alert pop-up reads as follows:

"WINDOWS ANTIVIRUS PRO ALERT
Infiltration Alert
Your computer is being attacked by an Internet Virus. It could be a password-stealing attack, a trojan-dropped or similar.
Details:
Attack from: 239.80.11.105, port 58962
Attacked port: 41567
Threat: HalfLemon
Do you want Windows Antivirus Pro to block this attack?"

The user is then prompted to purchase and download Windows Antivirus Pro in order to combat these fictitious threats. Do not be tricked into purchasing this fake spyware remover, and instead remove HalfLemon Infiltration Alert as soon as possible.

File System Details

HalfLemon Infiltration Alert may create the following file(s):
# File Name Detections
1. msvcp80.dll
2. dbsinit.exe
3. desot.exe
4. msvcm80.dll
5. Windows Antivirus Pro.exe
6. dddesot.dll
7. ANTI_files.exe
8. msvcr80.dll
9. svchast.exe
10. i1.gif
11. j1.gif
12. jj1.gif
13. l1.gif
14. pix.gif
15. up1.gif
16. w11.gif
17. w3.jpg
18. wt3.gif
19. bennuar.old
20. wispex.html
21. i3.gif
22. j3.gif
23. jj3.gif
24. l3.gif
25. t2.gif
26. w1.gif
27. w3.gif
28. wt2.gif
29. ppp4.dat
30. Desktop\\\\Windows Antivirus Pro.lnk
31. i2.gif
32. j2.gif
33. jj2.gif
34. l2.gif
35. t1.gif
36. up2.gif
37. w2.gif
38. wt1.gif
39. ppp3.dat
40. sysnet.dat

Registry Details

HalfLemon Infiltration Alert may create the following registry entry or registry entries:
HKEY_CLASSES_ROOT\CLSID\{425882B0-B0BF-11CE-B59F-00AA006CB37D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Win Antivirus Pro
HKEY_CURRENT_USER\Software\Windows Antivirus Pro
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F54AF7DE-6038-4026-8433-CC30E3F17212}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AntipPro2009_12
HKEY_CURRENT_USER\Software\Softimer
HKEY_CLASSES_ROOT\CLSID\{F54AF7DE-6038-4026-8433-CC30E3F17212}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AntipPro2009_12

Trending

Most Viewed

Loading...