Trojan.FakeAlert.TE

( Program:Win32/Antivirus2008, Adware/FakeAlert, Cryp_pai-5, Win32:FraudLoad-MH [Trj] )
Spreading: low
Damage: low
Size: 48,5 to 59 KB, or 858 to 863,5 KB
Discovered: 2008 Jun 24

SYMPTOMS:

  The presence of the file
     C:\Program Files\Antivirus2008\Antvrs.exe
 and the key
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run having a subkey named Antivirus pointing to it.
 

TECHNICAL DESCRIPTION:

   This application is a rogue antivirus that shows a fake system scan and misleading results (a very infected computer) in order to determine the user to register/buy this product.
   
The malware will run at every system startup, as it sets the following registry key:
     * HKCU\Software\Microsoft\Windows\CurrentVersion\Run
                * Antivirus -> C:\Program Files\Antivirus2008\Antvrs.exe 

The executable that downloads this file is detected by BitDefender with the same name(Trojan.FakeAlert.TE).



Removal instructions:

Please let BitDefender delete your infected files..

ANALYZED BY:

Boeriu Laura, virus researcher