TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
TROJ_FAKEAV.BLV
Overview

Malware type: Trojan

Aliases: No Alias Found

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

Low

Distribution potential:

Low

Description: 

This Trojan uses social engineering methods to lure users into performing certain actions that may, directly or indirectly, cause malicious routines to be performed. Specifically, it arrives as an attachment of a spammed email message.

To get a one-glance comprehensive view of the behavior of this malware, refer to the Threat Diagram shown below.

TROJ_FAKEAV.BLV Behavior Diagram

Malware Overview

This Trojan arrives as attachment to mass-mailed email messages. It may be downloaded by the malware detected by Trend Micro as TROJ_BREDLAB.SMF.

It displays fake alerts on the system tray:

It displays fake scanning process as shown below:

After the scan, this FAKEAV will ask the user to purchase the full version of the program to remove all threats. If the user agrees, he will be redirected to http://{BLOCKED}o-21.com where the software can be purchased as shown below:

It also asks for credit card information where it may lead to information theft.

This Trojan drops files. It also connects to a certain Web site.

This Trojan restarts the affected system. It is a rogue antivirus called Antivirus Pro 2010.

For additional information about this threat, see:
Solution
Technical Details

Description created: Nov. 2, 2009 11:50:30 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.