Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | August 2008 (4.32) |
| Protection available since | 2 July 2008 00:40:33 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/FakeAle-CV changes the background on the computer to show the warning message:
"Spyware detected on your computer! Install an antivirus or spyware remover to clean your computer"
Troj/FakeAle-CV installs a screensaver that gives the impression of the computer crashing and rebooting over and over again.
Troj/FakeAle-CV creates the following registry entries to prevent the user from changing the background and screensaver:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
NoDispBackgroundPage
1
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
NoDispScrSavPage
1
Troj/FakeAle-CV then tries to download a fraudulent anti-virus and spyware remover.
Troj/FakeAle-CV copies itself to <System>\lphcrrsj0el6c.exe.
Troj/FakeAle-CV drops the following clean files which can be safely deleted:
<System>\blphcrrsj0el16c.scr is a clean screensaver file
<System>\phcrrsj0el6c.bmp is the bitmap used for the computer background.
