|File Type||Win32 PE executable (.EXE)|
FakeFormat is a trojan program.
Once the program is run, it overwrites the boot sector and both FAT copies of diskette in drive A: assuming that there's a 1.44 mb diskette is there. After that a diskette boot sector contains a stub that will output
This is a DATA disk only; Insert system disk, press any key when ready.
The trojan waits for keypress and if CTRL + C combination is pressed exits to system, otherwise it loops (starts its code from the beginning).
Depending on the settings of the user's F-Secure security product, it will either automatically delete the program, quarantine or rename the suspect file, or ask the user for a desired action.