Sophos

Troj/PSW-GF

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 22 December 2008 16:23:42 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/PSW-GF is a Trojan for the Windows platform.

When run Troj/PSW-GF creates the files:
<system>\sigveri - detected as Troj/PSW-GF
<system>\PGPsc.sys - detected as Troj/NtRootK-EG
<system>\config\security.emf - clean file

A copy of the Trojan will also be created in the Windows temporary folder with a name that starts "cwh" followed by a random two digit number.

The following registry entry is modified:
HKLM\Software\Microsft\Windows NT\CurrentVersion\winlogon\shell
explorer.exe <system>\sigveri -l

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer