Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 28 March 2008 22:46:56 (GMT) |
| Last updated | 15 October 2009 23:36:23 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/FakeAle-AW is a Trojan for the Windows platform.
When first run Troj/FakeAle-AW copies itself to <System>\sbwltbxa.exe and creates the file <System>\winfrun32.bin. The file winfrun32.bin is not malicious and may be deleted.
The Trojan may also drop corrupt files with the names of real adware components.
The following registry entries are changed to run sbwltbxa.exe on startup:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
,<System>\sbwltbxa.exe,
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<System>\sbwltbxa.exe,
The following registry entries are set, disabling system software:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
DisableTaskMgr
1

