Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | June 2008 (4.30) |
| Protection available since | 26 April 2008 05:35:27 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/FakeVir-AY pretends to be an anti-spyware program called MalwareBell. It detects clean files on the victim computer as infected with malware, then attempts to scare the user into purchasing "the full version" of MalwareBell.
When run Troj/FakeVir-AY creates the following files:
<Program Files>\MalwareBell\malwarebell.exe - detected as Troj/FakeVir-AY
<Program Files>\MalwareBell\mb.db3 - data file, can be deleted
<Program Files>\MalwareBell\mb.db2 - data file, can be deleted
<Program Files>\MalwareBell\mbuninst.exe - clean; the uninstaller, can be deleted
Troj/FakeVir-AY provides an uninstall option which can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "MalwareBell". The uninstall option fails to remove Troj/FakeVir-AY from the computer.
Troj/FakeVir-AY creates the following registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\antispy
<Program Files>\MalwareBell\malwarebell.exe
HKCU\Software\MalwareBell\
