Sophos

Troj/FakeVir-AY

Aliases
  • FraudTool.Win32.MalwareBell.f
  • MalwareBell
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2008 (4.30)
Protection available since 26 April 2008 05:35:27 (GMT)
Detected by All Sophos products

Action

More Information

Troj/FakeVir-AY pretends to be an anti-spyware program called MalwareBell. It detects clean files on the victim computer as infected with malware, then attempts to scare the user into purchasing "the full version" of MalwareBell.

When run Troj/FakeVir-AY creates the following files:

<Program Files>\MalwareBell\malwarebell.exe - detected as Troj/FakeVir-AY
<Program Files>\MalwareBell\mb.db3 - data file, can be deleted
<Program Files>\MalwareBell\mb.db2 - data file, can be deleted
<Program Files>\MalwareBell\mbuninst.exe - clean; the uninstaller, can be deleted

Troj/FakeVir-AY provides an uninstall option which can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "MalwareBell". The uninstall option fails to remove Troj/FakeVir-AY from the computer.

Troj/FakeVir-AY creates the following registry entries:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\antispy
<Program Files>\MalwareBell\malwarebell.exe

HKCU\Software\MalwareBell\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer