Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | May 2008 (4.29) |
| Protection available since | 3 January 2008 09:01:38 (GMT) |
| Last updated | 25 March 2008 19:38:50 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Prorat-Gen is a family of Trojans for the Windows platform.
Members of Troj/Prorat-Gen usually copy themselves to another location, often to a filename such as <Program Files>\Update\winkey.exe, and drop a DLL file, for example <Program Files>\Update\winkey.dll. This dropped file is typically detected as Mal/Behav-119.
Members of Troj/Prorat-Gen usually register the copy of themselves as a new system driver service, with a name and display name decrypted from data appended to the file, and with a startup type of automatic so that it is started automatically during system startup. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services
