Sophos

Troj/FakeVir-DE

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from September 2008 (4.33)
Protection available since 10 July 2008 22:24:49 (GMT)
Detected by All Sophos products

Action

More Information

Troj/FakeVir-DE claims to be an anti-virus scanner called "Antivirus 2009".

Troj/FakeVir-DE scans the computer and reports clean files as being infected with malware. Troj/FakeVir-DE then persistently prompts the user to purchase the full version of "Antivirus 2009" in order to cleanup the infections.

When first run Troj/FakeVir-DE creates the following files:

- <System>\scui.cpl - detected as Troj/FakeVir-DE
- <Start Menu>\Antivirus 2009\Antivirus 2009.lnk - icon file, can be safely deleted
- <Start Menu>\Antivirus 2009\Uninstall Antivirus 2009.lnk - icon file, can be safely deleted
- <Desktop>\Antivirus 2009.lnk - icon file, can be safely deleted
- <Application Data>\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk - icon file, can be safely deleted.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer