TROJ_FAKEAV.GVJ
Windows 2000, Windows XP, Windows Server 2003

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
As of this writing, the said sites are inaccessible.
It deletes the initially executed copy of itself.
TECHNICAL DETAILS
Arrival Details
This Trojan may be unknowingly downloaded by a user while visiting the following malicious websites:
- http://{BLOCKED}gn.cl/umag7/ciencias/nav1.php
- http://{BLOCKED}rocesssolutionmicrosoft.info/bb61f9bcec711d56/1/
Installation
This Trojan drops the following copies of itself into the affected system:
- %User Profile%\Application Data\Protector-imal.exe
(Note: %User Profile% is the current user's profile folder, which is usually C:\Windows\Profiles\{user name} on Windows 98 and ME, C:\WINNT\Profiles\{user name} on Windows NT, and C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003.)
It drops the following files:
- %Desktop%\Windows Custodian Utility.lnk
- %Start Menu%\Programs\Windows Custodian Utility.lnk
- %User Profile%\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#local\settings.sol
- %Windows%\system32\d3d9caps.dat
It terminates the execution of the copy it initially executed and executes the copy it drops instead.
Autostart Technique
This Trojan adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
Inspector = "%User Profile%\Application Data\Protector-imal.exe"
Other System Modifications
This Trojan adds the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Main\FeatureControl\
FEATURE ERROR PAGE BYPASS ZONE CHECK FOR HTTPS KB954312
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Image File Execution Options\
{application name}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Image File Execution Options\
regedit.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Image File Execution Options\
taskmgr.exe
It adds the following registry entries:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings
WarnOnHTTPSToHTTPRedirect = "0"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Settings
GConfig = "{random values}"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Settings
net = "2012-4-5_3"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Settings
UID = "fmpltekpsu"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Internet Explorer\Main\FeatureControl\
FEATURE ERROR PAGE BYPASS ZONE CHECK FOR HTTPS KB954312
iexplore.exe = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\policies\
system
EnableLUA = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\policies\
system
ConsentPromptBehaviorAdmin = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\policies\
system
ConsentPromptBehaviorUser = "0"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Image File Execution Options\
{application name}
Debugger = "svchost.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Image File Execution Options\
taskmgr.exe
Debugger = "%User Profile%\Application Data\Protector-imal.exe task"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Image File Execution Options\
regedit.exe
Debugger = "%User Profile%\Application Data\Protector-imal.exe reg"
Where {application name} may be any of the following:
- avpm.exe
- avptc32.exe
- avpupd.exe
- avsched32.exe
- avshadow.exe
- avsynmgr.exe
- avupgsvc.exe
- AVWEBGRD.EXE
- avwin.exe
- avwin95.exe
- avwinnt.exe
- avwsc.exe
- avwupd.exe
- avwupd32.exe
- avwupsrv.exe
- avxmonitor9x.exe
- avxmonitornt.exe
- avxquar.exe
- b.exe
- backweb.exe
- bargains.exe
- bd_professional.exe
- bdfvcl.exe
- bdfvwiz.exe
- BDInProcPatch.exe
- bdmcon.exe
- BDMsnScan.exe
- BDSurvey.exe
- beagle.exe
- belt.exe
- bidef.exe
- bidserver.exe
- bipcp.exe
- bipcpevalsetup.exe
- bisp.exe
- blackd.exe
- blackice.exe
- blink.exe
- blss.exe
- bootconf.exe
- bootwarn.exe
- borg2.exe
- bpc.exe
- brasil.exe
- brastk.exe
- brw.exe
- bs120.exe
- bspatch.exe
- bundle.exe
- bvt.exe
- c.exe
- cavscan.exe
- ccapp.exe
- ccevtmgr.exe
- ccpxysvc.exe
- ccSvcHst.exe
- cdp.exe
- cfd.exe
- cfgwiz.exe
- cfiadmin.exe
- cfiaudit.exe
- cfinet.exe
- cfinet32.exe
- cfp.exe
- cfpconfg.exe
- cfplogvw.exe
- cfpupdat.exe
- claw95.exe
- claw95cf.exe
- clean.exe
- cleaner.exe
- cleaner3.exe
- cleanIELow.exe
- cleanpc.exe
- click.exe
- cmd32.exe
- cmdagent.exe
- cmesys.exe
- cmgrdian.exe
- cmon016.exe
- connectionmonitor.exe
- control
- cpd.exe
- cpf9x206.exe
- cpfnt206.exe
- crashrep.exe
- csc.exe
- cssconfg.exe
- cssupdat.exe
- cssurf.exe
- ctrl.exe
- cv.exe
- cwnb181.exe
- cwntdwmo.exe
- d.exe
- datemanager.exe
- dcomx.exe
- defalert.exe
- defscangui.exe
- defwatch.exe
- deloeminfs.exe
- deputy.exe
- divx.exe
- dllcache.exe
- dllreg.exe
- doors.exe
- dop.exe
- dpf.exe
- dpfsetup.exe
- dpps2.exe
- driverctrl.exe
- drwatson.exe
- drweb32.exe
- drwebupw.exe
- dssagent.exe
- dvp95.exe
- dvp95_0.exe
- ecengine.exe
- efpeadm.exe
- emsw.exe
- ent.exe
- esafe.exe
- escanhnt.exe
- escanv95.exe
- espwatch.exe
- ethereal.exe
- etrustcipe.exe
- evpn.exe
- exantivirus-cnet.exe
- exe.avxw.exe
- expert.exe
- explore.exe
- f-agnt95.exe
- f-prot.exe
- f-prot95.exe
- f-stopw.exe
- fact.exe
- fameh32.exe
- fast.exe
- fch32.exe
- fih32.exe
- findviru.exe
- firewall.exe
- fixcfg.exe
- fixfp.exe
- fnrb32.exe
- fp-win.exe
- fp-win_trial.exe
- fprot.exe
- frmwrk32.exe
- frw.exe
- fsaa.exe
- fsav.exe
- fsav32.exe
- fsav530stbyb.exe
- fsav530wtbyb.exe
- fsav95.exe
- fsgk32.exe
- fsm32.exe
- fsma32.exe
- fsmb32.exe
- gator.exe
- gav.exe
- gbmenu.exe
- gbn976rl.exe
- gbpoll.exe
- generics.exe
- gmt.exe
- guard.exe
- guarddog.exe
- guardgui.exe
- hacktracersetup.exe
- hbinst.exe
- hbsrv.exe
- History.exe
- homeav2010.exe
- hotactio.exe
- hotpatch.exe
- htlog.exe
- htpatch.exe
- hwpe.exe
- hxdl.exe
- hxiul.exe
- iamapp.exe
- iamserv.exe
- iamstats.exe
- ibmasn.exe
- ibmavsp.exe
- icload95.exe
- icloadnt.exe
- icmon.exe
- icsupp95.exe
- icsuppnt.exe
- Identity.exe
- idle.exe
- iedll.exe
- iedriver.exe
- IEShow.exe
- iface.exe
- ifw2000.exe
- inetlnfo.exe
- infus.exe
- infwin.exe
- init.exe
- init32.exe
- install[1].exe
- install[2].exe
- install[3].exe
- install[4].exe
- install[5].exe
- intdel.exe
- intren.exe
- iomon98.exe
- istsvc.exe
- jammer.exe
- jdbgmrg.exe
- jedi.exe
- JsRcGen.exe
- kavlite40eng.exe
- kavpers40eng.exe
- kavpf.exe
- kazza.exe
- keenvalue.exe
- kerio-pf-213-en-win.exe
- kerio-wrl-421-en-win.exe
- kerio-wrp-421-en-win.exe
- killprocesssetup161.exe
- ldnetmon.exe
- ldpro.exe
- ldpromenu.exe
- ldscan.exe
- licmgr.exe
- lnetinfo.exe
- loader.exe
- localnet.exe
- lockdown.exe
- lockdown2000.exe
- lookout.exe
- lordpe.exe
- lsetup.exe
- luall.exe
- luau.exe
- lucomserver.exe
- luinit.exe
- luspt.exe
- MalwareRemoval.exe
- mapisvc32.exe
- mcagent.exe
- mcmnhdlr.exe
- mcmpeng.exe
- mcmscsvc.exe
- mcnasvc.exe
- mcproxy.exe
- McSACore.exe
- mcshell.exe
- mcshield.exe
- mcsysmon.exe
- mctool.exe
- mcupdate.exe
- mcvsrte.exe
- mcvsshld.exe
- md.exe
- mfin32.exe
- mfw2en.exe
- mfweng3.02d30.exe
- mgavrtcl.exe
- mgavrte.exe
- mghtml.exe
- mgui.exe
- minilog.exe
- mmod.exe
- monitor.exe
- moolive.exe
- mostat.exe
- mpfagent.exe
- mpfservice.exe
- MPFSrv.exe
- mpftray.exe
- mrflux.exe
- mrt.exe
- msa.exe
- msapp.exe
- MSASCui.exe
- msbb.exe
- msblast.exe
- mscache.exe
- msccn32.exe
- mscman.exe
- msconfig
- msdm.exe
- msdos.exe
- msiexec16.exe
- mslaugh.exe
- msmgt.exe
- msmsgri32.exe
- msseces.exe
- mssmmc32.exe
- mssys.exe
- msvxd.exe
- mu0311ad.exe
- mwatch.exe
- n32scanw.exe
- nav.exe
- navap.navapsvc.exe
- navapsvc.exe
- navapw32.exe
- navdx.exe
- navlu32.exe
- navnt.exe
- navstub.exe
- navw32.exe
- navwnt.exe
- nc2000.exe
- ncinst4.exe
- ndd32.exe
- neomonitor.exe
- neowatchlog.exe
- netarmor.exe
- netd32.exe
- netinfo.exe
- netmon.exe
- netscanpro.exe
- netspyhunter-1.2.exe
- netutils.exe
- nisserv.exe
- nisum.exe
- nmain.exe
- nod32.exe
- normist.exe
- norton_internet_secu_3.0_407.exe
- notstart.exe
- npf40_tw_98_nt_me_2k.exe
- npfmessenger.exe
- nprotect.exe
- npscheck.exe
- npssvc.exe
- nsched32.exe
- nssys32.exe
- nstask32.exe
- nsupdate.exe
- nt.exe
- ntrtscan.exe
- ntvdm.exe
- ntxconfig.exe
- nui.exe
- nupgrade.exe
- nvarch16.exe
- nvc95.exe
- nvsvc32.exe
- nwinst4.exe
- nwservice.exe
- nwtool16.exe
- OAcat.exe
- OAhlp.exe
- OAReg.exe
- oasrv.exe
- oaui.exe
- oaview.exe
- ODSW.exe
- ollydbg.exe
- onsrvr.exe
- optimize.exe
- ostronet.exe
- otfix.exe
- outpost.exe
- outpostinstall.exe
- outpostproinstall.exe
- ozn695m5.exe
- padmin.exe
- panixk.exe
- patch.exe
- pav.exe
- pavcl.exe
- PavFnSvr.exe
- pavproxy.exe
- pavprsrv.exe
- pavsched.exe
- pavsrv51.exe
- pavw.exe
- pc.exe
- PC_Antispyware2010.exe
- pccwin98.exe
- pcfwallicon.exe
- pcip10117_0.exe
- pcscan.exe
- pctsAuxs.exe
- pctsGui.exe
- pctsSvc.exe
- pctsTray.exe
- pdfndr.exe
- pdsetup.exe
- PerAvir.exe
- periscope.exe
- persfw.exe
- personalguard
- personalguard.exe
- perswf.exe
- pf2.exe
- pfwadmin.exe
- pgmonitr.exe
- pingscan.exe
- platin.exe
- pop3trap.exe
- poproxy.exe
- popscan.exe
- portdetective.exe
- portmonitor.exe
- powerscan.exe
- ppinupdt.exe
- pptbc.exe
- ppvstop.exe
- prizesurfer.exe
- prmt.exe
- prmvr.exe
- procdump.exe
- processmonitor.exe
- procexplorerv1.0.exe
- programauditor.exe
- proport.exe
- protector.exe
- protectx.exe
- PSANCU.exe
- PSANHost.exe
- PSANToManager.exe
- PsCtrls.exe
- PsImSvc.exe
- PskSvc.exe
- pspf.exe
- PSUNMain.exe
- purge.exe
- qconsole.exe
- qh.exe
- qserver.exe
- Quick Heal.exe
- QuickHealCleaner.exe
- rapapp.exe
- rav7.exe
- rav7win.exe
- rav8win32eng.exe
- ray.exe
- rb32.exe
- rcsync.exe
- realmon.exe
- reged.exe
- regedt32.exe
- rescue.exe
- rescue32.exe
- rrguard.exe
- rscdwld.exe
- rshell.exe
- rtvscan.exe
- rtvscn95.exe
- rulaunch.exe
- rwg
- rwg.exe
- SafetyKeeper.exe
- safeweb.exe
- sahagent.exe
- Save.exe
- SaveArmor.exe
- SaveDefense.exe
- SaveKeep.exe
- savenow.exe
- sbserv.exe
- sc.exe
- scam32.exe
- scan32.exe
- scan95.exe
- scanpm.exe
- scrscan.exe
- Secure Veteran.exe
- secureveteran.exe
- Security Center.exe
- SecurityFighter.exe
- securitysoldier.exe
- serv95.exe
- setloadorder.exe
- setup_flowprotector_us.exe
- setupvameeval.exe
- sgssfw32.exe
- sh.exe
- shellspyinstall.exe
- shield.exe
- shn.exe
- showbehind.exe
- signcheck.exe
- smart.exe
- smartprotector.exe
- smc.exe
- smrtdefp.exe
- sms.exe
- smss32.exe
- snetcfg.exe
- soap.exe
- sofi.exe
- SoftSafeness.exe
- sperm.exe
- spf.exe
- sphinx.exe
- spoler.exe
- spoolcv.exe
- spoolsv32.exe
- spywarexpguard.exe
- spyxx.exe
- srexe.exe
- srng.exe
- ss3edit.exe
- ssg_4104.exe
- ssgrate.exe
- st2.exe
- start.exe
- stcloader.exe
- supftrl.exe
- support.exe
- supporter5.exe
- svc.exe
- svchostc.exe
- svchosts.exe
- svshost.exe
- sweep95.exe
- sweepnet.sweepsrv.sys.swnetsup.exe
- symlcsvc.exe
- symproxysvc.exe
- symtray.exe
- system.exe
- system32.exe
- sysupd.exe
- tapinstall.exe
- taumon.exe
- tbscan.exe
- tc.exe
- tca.exe
- tcm.exe
- tds-3.exe
- tds2-98.exe
- tds2-nt.exe
- teekids.exe
- tfak.exe
- tfak5.exe
- tgbob.exe
- titanin.exe
- titaninxp.exe
- TPSrv.exe
- trickler.exe
- trjscan.exe
- trjsetup.exe
- trojantrap3.exe
- TrustWarrior.exe
- tsadbot.exe
- tsc.exe
- tvmd.exe
- tvtmd.exe
- undoboot.exe
- updat.exe
- upgrad.exe
- utpost.exe
- vbcmserv.exe
- vbcons.exe
- vbust.exe
- vbwin9x.exe
- vbwinntw.exe
- vcsetup.exe
- vet32.exe
- vet95.exe
- vettray.exe
- vfsetup.exe
- vir-help.exe
- virusmdpersonalfirewall.exe
- VisthAux.exe
- VisthLic.exe
- VisthUpd.exe
- vnlan300.exe
- vnpc3000.exe
- vpc32.exe
- vpc42.exe
- vpfw30s.exe
- vptray.exe
- vscan40.exe
- vscenu6.02d30.exe
- vsched.exe
- vsecomr.exe
- vshwin32.exe
- vsisetup.exe
- vsmain.exe
- vsmon.exe
- vsstat.exe
- vswin9xe.exe
- vswinntse.exe
- vswinperse.exe
- w32dsm89.exe
- W3asbas.exe
- w9x.exe
- watchdog.exe
- webdav.exe
- WebProxy.exe
- webscanx.exe
- webtrap.exe
- wfindv32.exe
- whoswatchingme.exe
- wimmun32.exe
- win-bugsfix.exe
- win32.exe
- win32us.exe
- winactive.exe
- winav.exe
- windll32.exe
- window.exe
- windows Police Pro.exe
- windows.exe
- wininetd.exe
- wininitx.exe
- _avp32.exe
- _avpcc.exe
- _avpm.exe
- a.exe
- aAvgApi.exe
- AAWTray.exe
- About.exe
- ackwin32.exe
- Ad-Aware.exe
- adaware.exe
- advxdwin.exe
- AdwarePrj.exe
- agent.exe
- agentsvr.exe
- agentw.exe
- alertsvc.exe
- alevir.exe
- alogserv.exe
- AlphaAV
- AlphaAV.exe
- AluSchedulerSvc.exe
- amon9x.exe
- anti-trojan.exe
- Anti-Virus Professional.exe
- AntispywarXP2009.exe
- antivirus.exe
- AntiVirus_Pro.exe
- AntivirusPlus
- AntivirusPlus.exe
- AntivirusPro_2010.exe
- AntivirusXP
- AntivirusXP.exe
- antivirusxppro2009.exe
- ants.exe
- apimonitor.exe
- aplica32.exe
- apvxdwin.exe
- arr.exe
- ashAvast.exe
- ashBug.exe
- ashChest.exe
- ashCnsnt.exe
- ashDisp.exe
- ashLogV.exe
- ashMaiSv.exe
- ashPopWz.exe
- ashQuick.exe
- ashServ.exe
- ashSimp2.exe
- ashSimpl.exe
- ashSkPcc.exe
- ashSkPck.exe
- ashUpd.exe
- ashWebSv.exe
- aswChLic.exe
- aswRegSvr.exe
- aswRunDll.exe
- aswUpdSv.exe
- atcon.exe
- atguard.exe
- atro55en.exe
- atupdater.exe
- atwatch.exe
- au.exe
- aupdate.exe
- auto-protect.nav80try.exe
- autodown.exe
- autotrace.exe
- autoupdate.exe
- av360.exe
- avadmin.exe
- avastSvc.exe
- avastUI.exe
- AVCare.exe
- avcenter.exe
- avciman.exe
- avconfig.exe
- avconsol.exe
- ave32.exe
- AVENGINE.EXE
- avgcc32.exe
- avgchk.exe
- avgcmgr.exe
- avgcsrvx.exe
- avgctrl.exe
- avgdumpx.exe
- avgemc.exe
- avgiproxy.exe
- avgnsx.exe
- avgnt.exe
- avgrsx.exe
- avgscanx.exe
- avgserv.exe
- avgserv9.exe
- avgsrmax.exe
- avgtray.exe
- avguard.exe
- avgui.exe
- avgupd.exe
- avgw.exe
- avgwdsvc.exe
- avkpop.exe
- avkserv.exe
- avkservice.exe
- avkwctl9.exe
- avltmain.exe
- avmailc.exe
- avmcdlg.exe
- avnotify.exe
- avnt.exe
- avp32.exe
- winlogin.exe
- winmain.exe
- winppr32.exe
- winrecon.exe
- winservn.exe
- winssk32.exe
- winstart.exe
- winstart001.exe
- wintsk32.exe
- winupdate.exe
- wkufind.exe
- wnad.exe
- wnt.exe
- wradmin.exe
- wrctrl.exe
- wsbgate.exe
- wscfxas.exe
- wscfxav.exe
- wscfxfw.exe
- wsctool.exe
- wupdater.exe
- wupdt.exe
- wyvernworksfirewall.exe
- xp_antispyware.exe
- xpdeluxe.exe
- xpf202en.exe
- zapro.exe
- zapsetup3001.exe
- zatutor.exe
- zonalm2601.exe
- zonealarm.exe
- ~1.exe
- ~2.exe
- avpcc.exe
- avpdos32.exe
Download Routine
This Trojan accesses the following websites to download files:
- http://dl.{BLOCKED}box.com/u/69432480/NPSWF32.z
It saves the files it downloads using the following names:
- %User Profile%\Application Data\npswf32.tmp
(Note: %User Profile% is the current user's profile folder, which is usually C:\Windows\Profiles\{user name} on Windows 98 and ME, C:\WINNT\Profiles\{user name} on Windows NT, and C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003.)
As of this writing, the said sites are inaccessible.
Other Details
This Trojan connects to the following possibly malicious URL:
- http://{BLOCKED}int.{BLOCKED}esecstorage.info/?0=149&1=1&2=1&3=44&4=i&5=2600&6=5&7=1&8=62900.2180&9=1033&10=420&11=0000&12=fmpltekpsu&14=0
It deletes the initially executed copy of itself