Are you sure? I would say that it's probably an FP with Kaspersky but I can't recreate their warning. If you're a customer you should send them an email and advise them of the FP.
I'm a malware researcher for a major AV/AS and I've dissected the program and I don't see any malicious components or activities.
Ron Paul.exe doesn't open any ports or create any backdoors. I don't see any keyboard, or other type of system hooks. The program does hook the search results but most toolbars do. The search hook is created by FreeCause (
http://freecause.com/) and the program hooks the yahoo search engine.
I see links to We the People Radio Network, Ron Paul Radio, Ron Paul Revolution Radio, Lew Rockwell and Daily Dose. I don't see any malicious traffic.
The installer creates 3 exes and 12 dll's, none of which appear malicious and only standard registry entries appear under:
HKCR fctb18497.
HKCU software\fctb18497
HKCR freecauseurlsearchhook.fctoolbarurlsearchhook
HKLM software\fctb18497
HKLM software\classes\fctb18497.fctb18497
A few CLSID's
HKLM software\classes\clsid\{0d343d34-0c2c-4392-9a2e-7a803d752814}
HKLM software\classes\clsid\{aacaef9a-17e4-4ee8-a9cc-613b785caec6}
HKLM software\classes\clsid\{ee51cd61-6dd8-4470-9e0c-c97d332b3742}
HKLM software\classes\clsid\{eeb79245-1236-424c-a5de-bd1a510a05a6}
HKLM software\classes\typelib\{6790cb65-6299-4e9e-b653-b657bf8fa4b5}
HKLM software\classes\typelib\{7019c732-e9f7-4faa-a617-5ac14769c72f}
And a BHO
software\microsoft\windows\currentversion\explorer\browser helper objects\{ee51cd61-6dd8-4470-9e0c-c97d332b3742}
VirusTotal.com comes back clean from everyone but Clam and their diagnosis appears to be an FP because this definitely isn't a FakeAlert.
File Ron_Paul.exe received on 02.11.2008 18:00:59 (CET)
Current status: finished
Result: 1/32 (3.12%)
Compact Compact
Print results Print results
Antivirus Version Last Update Result
AhnLab-V3 2008.2.12.10 2008.02.11 -
AntiVir 7.6.0.62 2008.02.11 -
Authentium 4.93.8 2008.02.11 -
Avast 4.7.1098.0 2008.02.10 -
AVG 7.5.0.516 2008.02.11 -
BitDefender 7.2 2008.02.11 -
CAT-QuickHeal None 2008.02.11 -
ClamAV 0.92 2008.02.11 Adware.Fakealert-21
DrWeb 4.44.0.09170 2008.02.11 -
eSafe 7.0.15.0 2008.02.11 -
eTrust-Vet 31.3.5527 2008.02.11 -
Ewido 4.0 2008.02.11 -
FileAdvisor 1 2008.02.11 -
Fortinet 3.14.0.0 2008.02.11 -
F-Prot 4.4.2.54 2008.02.11 -
F-Secure 6.70.13260.0 2008.02.11 -
Ikarus T3.1.1.20 2008.02.11 -
Kaspersky 7.0.0.125 2008.02.11 -
McAfee 5226 2008.02.08 -
Microsoft 1.3204 2008.02.11 -
NOD32v2 2865 2008.02.11 -
Norman 5.80.02 2008.02.11 -
Panda 9.0.0.4 2008.02.10 -
Prevx1 V2 2008.02.11 -
Rising 20.29.22.00 2008.01.30 -
Sophos 4.26.0 2008.02.11 -
Sunbelt 2.2.907.0 2008.02.09 -
Symantec 10 2008.02.11 -
TheHacker 6.2.9.216 2008.02.11 -
VBA32 3.12.6.0 2008.02.10 -
VirusBuster 4.3.26:9 2008.02.11 -
Webwasher-Gateway 6.6.2 2008.02.11 -
Additional information
File size: 388592 bytes
MD5: 8429624a39b08a5ce5a27650de36af97
SHA1: 2d4ea8c50eb25b8f5bd9b5ced5dc22621d489feb
PEiD: -