Sophos

Troj/FakeAV-AQ

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from November 2008 (4.35)
Protection available since 24 July 2008 15:23:18 (GMT)
Last updated 18 September 2008 21:50:03 (GMT)
Detected by All Sophos products

Action

More Information

Troj/FakeAV-AQ claims to be an anti-virus scanner called "Antivirus XP 2008".

Troj/FakeAV-AQ scans the computer and reports clean files as being infected with malware.

When first run Troj/FakeAV-AQ drops the following files:

- <System>\<random name>.exe - detected as Troj/FakAlert-A
- <Program files>\<random name>\<random name>.exe - detected as Troj/FakeAV-AQ

Troj/FakeAV-AQ creates registry entries under:

HKLM\SOFTWARE\<random name>

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
<random name>

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
<random name>

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\
<random name>

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\AntivirXP08
AntivirXP08

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer