Sophos

Troj/Maran-AF

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2007 (4.18)
Protection available since 27 April 2007 19:15:50 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Maran-AF is a Trojan for the Windows platform.

Troj/Maran-AF includes functionality to download, install and run new software.

When Troj/Maran-AF is installed the following files are created:

<Windows>\alg.exe
<System>\delmeml.bat
<System>\oksound.dll

The files alg.exe and oksound.dll are detected as Mal/EncPk-F.

The file alg.exe is registered as a new system driver service named "PCIDown", with a display name of "PCI Adapter" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\PCIDown

Sophos's anti-virus products include Behavioral Genotype® Protection, which can proactively guard against new threats without requiring an update. Sophos customers have been protected against Troj/Maran-AF (detected as Mal/EncPk-F) since version 4.17.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer