Sophos

Troj/FakeAle-AM

Aliases
  • not-a-virus:FraudTool.Win32.WorldSecurityOnline.d
  • W32/Trojan.YEZ
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from June 2007 (4.18)
Protection available since 17 April 2007 20:43:04 (GMT)
Last updated 26 April 2007 05:31:26 (GMT)
Detected by All Sophos products

Action

More Information

Troj/FakeAle-AM drops the file <System>\higehsg.dll (detected separately as Mal/FakeVir-C) and downloads/installs the anti-spyware application SpyDawn from www.spydawn.com (detected separately as application SpyDawn).

The SpyDawn application then detects the file <System>\higehsg.dll as unwanted spyware and recommends that the user purchase the full version of SpyDawn in order to remove the unwanted spyware.

The file higehsg.dll is registered as a COM object, creating registry entries under:

HKCR\CLSID\{2016a466-91a2-43c6-97d8-2fd380f065ef}

The following registry entries are created to run code exported by higehsg.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
eitheror
{2016a466-91a2-43c6-97d8-2fd380f065ef}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{2016a466-91a2-43c6-97d8-2fd380f065ef}
eitheror

Registry entries are created under:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\System Alert Popup

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer