Virus:TR/FakeAV.ahx.1
Date discovered:24/05/2011
Type:Trojan
In the wild:No
Reported Infections:Low
Distribution Potential:Low
Damage Potential:Low
Static file:Yes
File size:1.761.280 Bytes
MD5 checksum:638f60ed1fd4531ca50d6b4cd29bd0dd
VDF version:7.11.08.122 - Tuesday, May 24, 2011
IVDF version:7.11.08.122 - Tuesday, May 24, 2011

 General Method of propagation:
   • No own spreading routine


Aliases:
   •  Sophos: Mal/FakeAV-MJ
   •  Bitdefender: Trojan.Generic.KDV.247543
   •  AVG: FakeAlert.ADU
   •  Grisoft: FakeAlert.ADU
   •  Eset: Win32/Adware.PrivacyGuard2010.AZ
   •  DrWeb: Trojan.FakeAV.5867


Platforms / OS:
   • Windows 95
   • Windows 98
   • Windows 98 SE
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003
   • Windows Vista
   • Windows Server 2008
   • Windows 7


Side effects:
   • Disable security applications
   • Falsely reports malware infection or system problems and offers to fix them if the user buys the application.
   • Lowers security settings
   • Registry modification
   • Steals information


Right after execution the following information is displayed:








Right after execution it runs windows applications which will display the following windows:



Description inserted by Jason Soo on Friday, June 17, 2011
Description updated by Jason Soo on Friday, June 17, 2011

Back . . . .
https:// This window is encrypted for your security.