Sophos

Troj/Junet-A

Aliases
  • PWS-Junet
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 12 November 2004 08:58:49 (GMT)
Last updated 11 October 2005 19:27:47 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Junet-A is a password stealing Trojan. The Trojan copies itself to the Windows folder as winuser.exe and to the Windows system folder as usrh.exe. Troj/Junet-A may then attempt to contact the website http://au-sales.net without the user's knowledge.

The Trojan monitors the sites that are visited using Internet Explorer. When the infected computer is used to access secure websites that have certain strings in the titlebar Troj/Junet-A will record information from the site and report it via the web. The strings that Troj/Junet-A looks for are:

"Sign In"
"Log In"
"Yahoo! Mail"
"NetZero Email on the We"
"Juno Email on the We"
"Cardmember Services"
"https://"
"BES"

Troj/Junet-A may add the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
User Logon = "<Windows system folder>\usrh.exe"

HKLM\Software\NVMark

HKCU\Software\Microsoft\Windows NT\CurrentVersion
run = "<Windows folder>\winuser.exe"

NOTE: On versions of Windows before Windows XP the win.ini file may be changed instead of the registry entry above.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer