Sophos

Troj/FakeAle-AW

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 28 March 2008 22:46:56 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/FakeAle-AW is a Trojan for the Windows platform.

When first run Troj/FakeAle-AW copies itself to <System>\sbwltbxa.exe and creates the file <System>\winfrun32.bin. The file winfrun32.bin is not malicious and may be deleted.

The Trojan may also drop corrupt files with the names of real adware components.

The following registry entries are changed to run sbwltbxa.exe on startup:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
,<System>\sbwltbxa.exe,

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<System>\sbwltbxa.exe,

The following registry entries are set, disabling system software:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
DisableTaskMgr
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer