Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | June 2008 (4.30) |
| Protection available since | 11 April 2008 19:01:35 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
When Troj/FakeVir-AW is installed it creates the file <System>\rkvdr.dll - also detected as Troj/FakeVir-AW.
The file rkvdr.dll is registered as a COM object, creating registry entries under:
HKCR\CLSID\{65bbf06c-ea06-4818-92a3-f3550d0e1004}
The following registry entry is created to run code exported by rkvdr.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{65bbf06c-ea06-4818-92a3-f3550d0e1004}
asparagine
Registry entries are created under:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert
Troj/FakeVir-AW provides an uninstall option which can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "Windows Safety Alert".
