Sophos

Troj/PWS-ARC

Aliases
  • Backdoor:Win32/Poisonivy.E
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2008 (4.30)
Protection available since 24 April 2008 07:26:46 (GMT)
Detected by All Sophos products

Action

More Information

Troj/PWS-ARC is a keylogging Trojan for the Windows platform.

When run Troj/PWS-ARC copies itself to <System>\mstscax.exe and records keystrokes and stores them into the file <System>\mstscax. The file mstscax can be safely deleted.

Troj/PWS-ARC sets the following registry entry:

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{798A2DF9-DF36-A957-C2F4-452346372BA1}
StubPath
<System32>\mstscax.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer