Threat Search: 

ThreatExpert's Statistics for Mal/FakeVir-G [Sophos]:

Mal/FakeVir-G [Sophos] is also known as:
Threat AliasNumber of Incidents
Trojan.Fakealert [Ikarus]30
not-a-virus:FraudTool.Win32.AntiVirusPro.ns [Kaspersky Lab]28
Trojan.Win32.FakeScanti [Ikarus]18
Trojan.Fakeavalert [Symantec]16
not-a-virus:FraudTool.Win32.AntiVirusPro.ng [Kaspersky Lab]14
Win-Trojan/Xema.variant [AhnLab]7
Trojan:Win32/FakeRemoc [Microsoft]6
WindowsAntivirusPro [Symantec]6
Win-Trojan/Fakealert.696320 [AhnLab]5
AntiVirus2008 [Symantec]4
not-a-virus:FraudTool.Win32.WinAntiVirus.kj [Kaspersky Lab]4
not-a-virus:FraudTool.Win32.WinAntiVirus.kz [Kaspersky Lab]4
not-a-virus:FraudTool.Win32.WinAntiVirus.mc [Kaspersky Lab]4
VirusRemover2008 [Symantec]4
Generic.Win32.Malware [Ikarus]3
not-a-virus:FraudTool.Win32.SecurityCenter.aq [Kaspersky Lab]3
not-a-virus:FraudTool.Win32.WinAntiVirus.lp [Kaspersky Lab]3
Program:Win32/Winfixer [Microsoft]3
Trojan-PSW.Win32.Agent.mgm [Kaspersky Lab]3
Trojan-PWS.Win32.Agent [Ikarus]3
AntiVirus2009 [Symantec]2
Generic.dx!bd [McAfee]2
not-a-virus:FraudTool.Win32.SpywareRemover2009.c [Kaspersky Lab]2
not-a-virus:FraudTool.Win32.VirusRemover.bn [Kaspersky Lab]2
not-a-virus:FraudTool.Win32.VirusRemover.by [Kaspersky Lab]2
Trojan.Win32.FakeRemoc [Ikarus]2
Winfixer [McAfee]2
CoreGuardAntivirus2009 [Symantec]1
FakeAlert-BB [McAfee]1
FakeAlert-CoreGuard [McAfee]1
not-a-virus:FraudTool.Win32.Agent.nn [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.SecurityCenter.an [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.SpywareRemover [Ikarus]1
not-a-virus:FraudTool.Win32.SpywareRemover.e [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.SpywareRemover.f [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.SpywareRemover2009 [Ikarus]1
not-a-virus:FraudTool.Win32.WinAntiVirus.ku [Kaspersky Lab]1
not-a-virus:FraudTool.Win32.WinAntiVirus.le [Kaspersky Lab]1
Trojan.Win32.FakeCog [Ikarus]1
Trojan:Win32/FakeCog [Microsoft]1
Virus.Win32.Virut.ce [Kaspersky Lab]1
Virus:Win32/Virut.BM [Microsoft]1
VirusDoctor [Symantec]1
W32.Virut.CF [Symantec]1
W32/Virut.n.gen [McAfee]1
Win32/Virut.F [AhnLab]1

Mal/FakeVir-G [Sophos] has the following possible countries of origin:
OriginNumber of Incidents
Russian Federation8
Ukraine6

Mal/FakeVir-G [Sophos] is known to be created as:
%ProgramFiles%\spywareremover2009\cn.exe
%ProgramFiles%\spywareremover2009\sr.exe
%ProgramFiles%\virusremover2009\uninstall.exe
%ProgramFiles%\virusremover2009\vrm2009.exe
Note: %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.