Troj/FakeAle-AX is a Trojan for the Windows platform.

When first run Troj/FakeAle-AX copies itself to \sbwltbxa.exe and creates the file \winfrun32.bin.

The following registry entries are changed to run sbwltbxa.exe on startup:


HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon Userinit
System\sbwltbxa.exe,
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Userinit
System\userinit.exe,\sbwltbxa.exe,

The following registry entries are set, disabling system software:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System DisableTaskMgr
1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system DisableTaskMgr
1

More information can be found at this Sophos page.