TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
TROJ_FAKEAV.BBM
Overview

Malware type: Trojan

Aliases: FakeAlert-BY (McAfee),

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

Medium

Distribution potential:

Low

Description: 

To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.

TROJ_FAKEAV.BBM Behavior Diagram

Malware Overview

This Trojan may be downloaded from certain remote sites.

It creates folders. It drops copies of itself.It drops files/components. It creates registry entries to enable its automatic execution at every system startup. It creates registry key(s)/entry(ies).

This fake antivirus program stems from the news of Farrah Fawcett's death. Users trying to search for this may be pointed to a Web site which eventually leads to another site. Users are then prompted with a malware detection.

Clicking the "Cancel" button produces another pop-up. After the user clicks "OK", the first pop-up shows up again and this goes on until the user finally agrees to download the SystemSecurity software.

Upon installation, it displays the following:

It deletes itself after execution.

For additional information about this threat, see:
Solution
Technical Details

Description created: Jun. 25, 2009 9:05:23 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.