TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
TROJ_FAKEAV.NN
Overview

Malware type: Trojan

Aliases: No Alias Found

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

Medium

Distribution potential:

Low

Description: 

Trend Micro threat researchers post findings and analyses on various threats in real-time at the Malware Blog. Users can find more information about this specific threat here.

To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.

TROJ_FAKEAV.NN Behavior Diagram

Malware Overview

This Trojan may be downloaded from remote sites by other malware. It may be dropped by other malware. It may be downloaded unknowingly by a user when visiting malicious Web sites.

It creates folders. It drops files/components.

Upon execution, it displays the following graphical user interface (GUI) of a fake antivirus software:

It deletes itself after execution.

It creates registry entries to enable its automatic execution at every system startup. It also creates registry keys as part of its installation routine.

It accesses URLs to download files. It then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.

For additional information about this threat, see:
Solution
Technical Details

Description created: Sep. 20, 2008 12:27:55 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.