Trojan.FakeAV.SQ
LOW
MEDIUM
~182kb
(Win32:Xpantivirus-J)
Symptoms
After surfing on infected websites the user is infected with rogue antivirus applications such as "Antivirus 2009", AV360 or Total Security.
Removal instructions:
Please let BitDefender disinfect your files.
Analyzed By
Daniel Chipiristeanu, virus researcher
Technical Description:
The malware downloads other badware such as rogue antiviruses that claim to scan your computer, but they only detect false infections in order to trick the user into buying the product. ( Message of confirmation for the install of rogue antivirus : "This program will download and install Total Security on your PC." ). The rogue "Total Security" is a relative of the famous "XP Antivirus" scareware family.
It adds itself on startup using the following registry key : Software\Microsoft\Windows\CurrentVersion\Run. Also it protects against common used tools by researchers, if any are found an error occurs and the file is deleted.
SHARE
THIS ON