Virus:TR/FakeSC.A
Date discovered:06/08/2010
Type:Trojan
In the wild:Yes
Reported Infections:Low to medium
Distribution Potential:Low to medium
Damage Potential:Low to medium
Static file:Yes
File size:151.093 Bytes
MD5 checksum:ac87a1dcaa66a5b0ef19f10Ac6cc4022
IVDF version:7.10.10.99 - Friday, August 6, 2010

 General Method of propagation:
   • No own spreading routine


Aliases:
   •  Avast: Win32:Genome-IO
   •  VirusBuster: Trojan.HTML.Fraud.O
   •  Eset: Win32/Adware.WinAntiVirus


Platforms / OS:
   • Windows 98
   • Windows 98 SE
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003
   • Windows Vista
   • Windows Server 2008
   • Windows 7
   • Linux
   • Unix
   • OS/2
   • Mac


Side effects:
   • Drops files
   • Falsley reports malware infection or system problems and offers to fix them if the user buys the application.
   • Redirects to an infected website


 Files  It creates the following directory:
   • %malware execution directory%\images



The following files are created:

%malware execution directory%\images\i1.gif
%malware execution directory%\images\i2.gif
%malware execution directory%\images\i3.gif
%malware execution directory%\images\j1.gif
%malware execution directory%\images\j2.gif
%malware execution directory%\images\j3.gif
%malware execution directory%\images\jj1.gif
%malware execution directory%\images\jj2.gif
%malware execution directory%\images\jj3.gif
%malware execution directory%\images\l1.gif
%malware execution directory%\images\l2.gif
%malware execution directory%\images\l3.gif
%malware execution directory%\images\pix.gif
%malware execution directory%\images\t1.gif
%malware execution directory%\images\t2.gif
%malware execution directory%\images\Thumbs.db
%malware execution directory%\images\up1.gif
%malware execution directory%\images\up2.gif
%malware execution directory%\images\w1.gif
%malware execution directory%\images\w11.gif
%malware execution directory%\images\w2.gif
%malware execution directory%\images\w3.jpg
%malware execution directory%\images\word.doc
%malware execution directory%\images\wt1.gif
%malware execution directory%\images\wt2.gif
%malware execution directory%\images\wt3.gif
%malware execution directory%\wispex.html

Description inserted by Patrick Schoenherr on Friday, August 6, 2010
Description updated by Patrick Schoenherr on Friday, August 6, 2010

Back . . . .