Sophos

Troj/Prorat-Gen

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Included in our products from April 2008 (4.29)
Protection available since 3 January 2008 09:01:38 (GMT)
Last updated 25 March 2008 19:38:50 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Prorat-Gen is a family of Trojans for the Windows platform.

Members of Troj/Prorat-Gen usually copy themselves to another location, often to a filename such as <Program Files>\Update\winkey.exe, and drop a DLL file, for example <Program Files>\Update\winkey.dll. This dropped file is typically detected as Mal/Behav-119.

Members of Troj/Prorat-Gen usually register the copy of themselves as a new system driver service, with a name and display name decrypted from data appended to the file, and with a startup type of automatic so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer