Sophos

Troj/FakeAV-F

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from April 2008 (4.29)
Protection available since 26 March 2008 05:34:06 (GMT)
Detected by All Sophos products

Action

More Information

Troj/FakeAV-F is a Trojan for the Windows platform.

Troj/FakeAV-F presents the user witha fraudulent security alert and tries to trick the user into downloading and installing additional malware.

Troj/FakeAV-F makes changes under the following registry entry to prevent the user from accessing the task manager.
Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr

When first run Troj/FakeAV-F copies itself to <System>\sbwltbxa.exe and creates the file <System>\winfrun32.bin.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer