Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 12 November 2004 08:58:49 (GMT) |
| Last updated | 11 October 2005 19:27:47 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Junet-A is a password stealing Trojan. The Trojan copies itself to the Windows folder as winuser.exe and to the Windows system folder as usrh.exe. Troj/Junet-A may then attempt to contact the website http://au-sales.net without the user's knowledge.
The Trojan monitors the sites that are visited using Internet Explorer. When the infected computer is used to access secure websites that have certain strings in the titlebar Troj/Junet-A will record information from the site and report it via the web. The strings that Troj/Junet-A looks for are:
"Sign In"
"Log In"
"Yahoo! Mail"
"NetZero Email on the We"
"Juno Email on the We"
"Cardmember Services"
"https://"
"BES"
Troj/Junet-A may add the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
User Logon = "<Windows system folder>\usrh.exe"
HKLM\Software\NVMark
HKCU\Software\Microsoft\Windows NT\CurrentVersion
run = "<Windows folder>\winuser.exe"
NOTE: On versions of Windows before Windows XP the win.ini file may be changed instead of the registry entry above.
