Sophos

Sophos blogs

Troj/Keylog-HD

Aliases
  • Backdoor.Win32.Agent.aec
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 27 July 2006 22:26:36 (GMT)
Last updated 6 October 2006 07:09:18 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Keylog-HD is a Trojan for the Windows platform.

Troj/Keylog-HD includes functionality to access the internet and communicate with a remote server via HTTP. Troj/Keylog-HD is a Trojan for the Windows platform.

Troj/Keylog-HD includes functionality to access the internet and communicate with a remote server via HTTP.

When first run Troj/Keylog-HD displays a slideshow of 3 photos called "Victoria Stasova" with three different pictures. The Trojan silently copies itself to <Windows folder>\svchst.exe and creates the file <Windows>\svchst<##>.dll, where <##> is a random two digit number.

The following registry entry is created to run svchst.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
svchst
<Windows folder>\svchst.exe

Registry entries are created under:

HKLM\SOFTWARE\Ezhik\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer