Antivirus and Security Software from Sophos

Sophos blogs

Troj/FakeAV-AJE

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 29 November 2009 23:02:10 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/FakeAV-AJE is a Trojan for the Windows platform.

Troj/FakeAV-AJE includes functionality to:

- steal confidential information
- access the internet and communicate with a remote server via HTTP

When Troj/FakeAV-AJE is installed the following files are created:

<Temp>\7zS1.tmp\AntiSpywareBot\AntiSpywareBot.exe
<Temp>\7zS1.tmp\AntiSpywareBot\AntiSpywareBot.srv.exe
<Temp>\7zS1.tmp\AntiSpywareBot\Difxapi.dll
<Temp>\7zS1.tmp\AntiSpywareBot\FilterDrv\AntiSpywareBot.amd64.sys
<Temp>\7zS1.tmp\AntiSpywareBot\FilterDrv\AntiSpywareBot.x86.sys
<Temp>\7zS1.tmp\AntiSpywareBot\SpyCleaner.dll
<Temp>\7zS1.tmp\AntiSpywareBot\TCL.dll
<Temp>\7zS1.tmp\AntiSpywareBot\zlib.dll
<Temp>\7zS1.tmp\MSIStart.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer