1. Symantec-Broadcom-Horizontal/
  2. Security Response/
  3. Attack Signatures/
  4. System Infected: Trojan.Fakeransomdel Activity

System Infected: Trojan.Fakeransomdel Activity

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.


This signature detect Trojan.Fakeavlock activity on the infected computers.

Additional Information

When the Trojan is executed, it creates the following file:
%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe

The Trojan appears as a security application with the title Security Shield and reports false or exaggerated system security threats on the computer.


  • Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube