Sophos

Troj/FakeVir-BB

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2008 (4.31)
Protection available since 11 May 2008 19:55:38 (GMT)
Detected by All Sophos products

Action

More Information

Troj/FakeVir-BB claims to be an anti-virus scanner called "XP antivirus protection". Troj/FakeVir-BB scans the computer and reports clean files as being infected with malware.

When Troj/FakeVir-BB is installed the following files are created:

<User>\Application Data\Microsoft\Internet Explorer\Quick Launch\XP Antivirus 2008.lnk - can be safely deleted
<Desktop>\XP Antivirus 2008.lnk - can be safely deleted
<User>\Start Menu\XP Antivirus 2008\Uninstall XP Antivirus 2008.lnk - can be safely deleted
<User>\Start Menu\XP Antivirus 2008\XP Antivirus 2008.lnk - can be safely deleted

The following registry entry is set:

HKLM\SOFTWARE\Microsoft\Internet Explorer
UserSession
5C2F7C663FF054B7E092381A7908D41A

Registry entries are created under:

HKCU\Software\5C2F7C663FF054B7E092381A7908D41A\Options

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer