Sophos

Troj/PWS-ATF

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from October 2008 (4.34)
Protection available since 7 September 2008 15:49:56 (GMT)
Detected by All Sophos products

Action

More Information

Troj/PWS-ATF is a password stealing Trojan for the Windows platform.

Troj/PWS-ATF typically arrives as an email attachment.

When first run Troj/PWS-ATF copies itself to <System>\oembios.exe and changes the following registry entry to run itself on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<System>\oembios.exe,

The following (harmless) data files are created:

<System>\config\systemprofile\Application Data\sysproc64\sysproc32.sys
<System>\sysproc64\sysproc32.sys
<System>\sysproc64\sysproc86.sys

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer