Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 24 September 2005 14:57:39 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Keylog-AN is a password stealing Trojan which attempts to steal confidential information and send it to a remote location.
Troj/Keylog-AN includes functionality to steal confidential information including user account information, dial-up information, and passwords from Outlook Express and other email related applications.
When first run Troj/Keylog-AN copies itself to <Windows system folder>\service\explorer.exe and creates the file <Windows system folder>\service\dllp.txt. It may also create the following files:
<Windows system folder>\service\dllw.txt
<Windows system folder>\service\dlls.txt
<Windows system folder>\service\dll<random number>.txt
<Windows system folder>\\service\reoxconf1.sp
<Windows system folder>\service\reoxconf.sp
<Windows system folder>\service\reoxconf1.sam
<Windows system folder>\service\reoxconf.sam
<Windows system folder>\service\reoxconf.dl
<Windows system folder>\service\scr<random number>.html
These files are not malicious and may be safely deleted.
The following registry entry may be created to run explorer.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
<number>
<Windows system folder>\service\explorer.exe
Troj/Keylog-AN may disable Windows Firewall and may attempt to automatically close security warning messages displayed by common anti-virus and security related applications.
The following registry entries may be set, affecting internet security:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile\
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile
DisableNotifications
1
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile
EnableFirewall
0
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile
DoNotAllowExceptions
0
Troj/Keylog-AN may modify the HOSTS file which maps the URLs of selected websites to its own IP addresses, in order to affect redirection and therefore hijack browsing.
