Sophos

Troj/PWS-AQH

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 14 March 2008 23:11:43 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/PWS-AQH is a Trojan for the Windows platform.

When Troj/PWS-AQH is installed the following files are created:

<Temp>\RarSFX0\11.sfx.exe
<Temp>\RarSFX0\mm\168_325566_f54679f96e1c490 [%P].jpg
<Temp>\RarSFX0\mm\168_378561_7ccc6cb8001c00f [%P].jpg
<Temp>\RarSFX0\mm\2005610010104150 [%P].jpg
<Temp>\RarSFX0\mm\242965581_9faa239705_o [%P].jpg
<Temp>\RarSFX0\mm\Thumbs.db
<Temp>\RarSFX0\mm\harajuku-15 [%P].jpg
<Temp>\RarSFX0\mm\harajuku-6 [%P].jpg
<Current Folder>\2.bat
<Windows>\help\F3C74E3FA248.dll
<Windows>\help\F3C74E3FA248.xe

The file F3C74E3FA248.dll is detected as Mal/LineDLL-B and the file F3C74E3FA248.xe is detected as Mal/EncPk-AZ.

The file F3C74E3FA248.dll is registered as a COM object, creating registry entries under:

HKCR\CLSID\{1DBD6574-D6D0-4782-94C3-69619E719765

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer