Sophos

Troj/FakeAle-CV

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from August 2008 (4.32)
Protection available since 2 July 2008 00:40:33 (GMT)
Detected by All Sophos products

Action

More Information

Troj/FakeAle-CV changes the background on the computer to show the warning message:
"Spyware detected on your computer! Install an antivirus or spyware remover to clean your computer"

Troj/FakeAle-CV installs a screensaver that gives the impression of the computer crashing and rebooting over and over again.

Troj/FakeAle-CV creates the following registry entries to prevent the user from changing the background and screensaver:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
NoDispBackgroundPage
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
NoDispScrSavPage
1

Troj/FakeAle-CV then tries to download a fraudulent anti-virus and spyware remover.

Troj/FakeAle-CV copies itself to <System>\lphcrrsj0el6c.exe.

Troj/FakeAle-CV drops the following clean files which can be safely deleted:
<System>\blphcrrsj0el16c.scr is a clean screensaver file
<System>\phcrrsj0el6c.bmp is the bitmap used for the computer background.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer