Sophos

Troj/FakeVir-AW

Aliases
  • Hoax.Win32.Agent.bv
  • Hoax.Win32.Renos.bmq
  • SPR/FakeVirus.19968
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 11 April 2008 19:01:35 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

When Troj/FakeVir-AW is installed it creates the file <System>\rkvdr.dll - also detected as Troj/FakeVir-AW.

The file rkvdr.dll is registered as a COM object, creating registry entries under:

HKCR\CLSID\{65bbf06c-ea06-4818-92a3-f3550d0e1004}

The following registry entry is created to run code exported by rkvdr.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{65bbf06c-ea06-4818-92a3-f3550d0e1004}
asparagine

Registry entries are created under:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert

Troj/FakeVir-AW provides an uninstall option which can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "Windows Safety Alert".

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer