Sophos

Troj/FakeAv-V

Aliases
  • Trojan-Downloader.Win32.FraudLoad.bal
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from August 2008 (4.32)
Protection available since 12 June 2008 22:49:31 (GMT)
Detected by All Sophos products

Action

More Information

Troj/FakeAv-V is a Trojan for the Windows platform.

Troj/FakeAv-V includes functionality to access the internet and communicate with a remote server via HTTP.

When Troj/FakeAv-V is installed the following files are created:

<User>\Application Data\Microsoft\Internet Explorer\Quick Launch\XP Antivirus 2008.lnk
<Desktop>\XP Antivirus 2008.lnk
<User>\Start Menu\XP Antivirus 2008\Uninstall XP Antivirus 2008.lnk
<User>\Start Menu\XP Antivirus 2008\XP Antivirus 2008.lnk
<System>\scui.cpl

The following registry entry is set:

HKLM\SOFTWARE\Microsoft\Internet Explorer
UserSession
9FB3C0FC9EAC7A54541A0580ED344481

Registry entries are created under:

HKCU\Software\9FB3C0FC9EAC7A54541A0580ED344481\Options

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer