Sophos

Troj/FakeAle-FM

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 18 August 2008 18:54:06 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/FakeAle-FM is a Trojan for the Windows platform.

When Troj/FakeAle-FM is installed the following files are created:

<User>\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk
<User>\Cookies\user@google.co[1].txt
<User>\Cookies\user@google[2].txt
<Desktop>\Antivirus 2009.lnk
<User>\Local Settings\Application Data\Microsoft\Internet Explorer\msimgsiz.dat
<Temporary Internet Files>\Content.IE5\1xkoah28\2[1].jpg
<Temporary Internet Files>\Content.IE5\1xkoah28\images[1].jpg
<Temporary Internet Files>\Content.IE5\1xkoah28\tips[1].gif
<Temporary Internet Files>\Content.IE5\1xkoah28\winsystem[1].dll
<Temporary Internet Files>\Content.IE5\dqelb3r1\google.co[1]
<Temporary Internet Files>\Content.IE5\dqelb3r1\images[1].jpg
<Temporary Internet Files>\Content.IE5\dqelb3r1\nav_logo3[1].png
<Temporary Internet Files>\Content.IE5\fifz1988\images[1].jpg
<Temporary Internet Files>\Content.IE5\fifz1988\nav_logo3[1].png
<Temporary Internet Files>\Content.IE5\fifz1988\olympics08_pingpong[1].gif
<Temporary Internet Files>\Content.IE5\qqt713pm\google.co[1].htm
<Temporary Internet Files>\Content.IE5\qqt713pm\search[1]
<Temporary Internet Files>\Content.IE5\qqt713pm\search[1].htm
<User>\Start Menu\Antivirus 2009\Antivirus 2009.lnk
<User>\Start Menu\Antivirus 2009\Uninstall Antivirus 2009.lnk
<User>\UserData\index.dat
<Program Files>\av9\av2009.exe
<Root>\Recycled\info2
<System>\ieupdates.exe
<System>\scui.cpl
<System>\winsrc.dll

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer