Sophos

Troj/PWS-ATP

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Protection available since 15 September 2008 07:23:44 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/PWS-ATP is a Trojan for the Windows platform.

When run Troj/PWS-ATP creates the files:
<Windows>\Debug\winhlp.dll - detectedd as Mal/LineDLL-B

and copies itself to <System>\helpme.exe.

The following registry entries are set:

HKCR\CLSID\{4B00FA89-7C1A-41F1-AF62-C7FF0D3B96A7}
(default)
url

HKCR\CLSID\{4B00FA89-7C1A-41F1-AF62-C7FF0D3B96A7}\InProcServer32
(default)
<Windows>\Debug\winhlp.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{4B00FA89-7C1A-41F1-AF62-C7FF0D3B96A7}

Troj/PWS-ATP also drops a non-malicious GIF image which is then opened by the default image viewer application.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer