Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 15 September 2008 07:23:44 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/PWS-ATP is a Trojan for the Windows platform.
When run Troj/PWS-ATP creates the files:
<Windows>\Debug\winhlp.dll - detectedd as Mal/LineDLL-B
and copies itself to <System>\helpme.exe.
The following registry entries are set:
HKCR\CLSID\{4B00FA89-7C1A-41F1-AF62-C7FF0D3B96A7}
(default)
url
HKCR\CLSID\{4B00FA89-7C1A-41F1-AF62-C7FF0D3B96A7}\InProcServer32
(default)
<Windows>\Debug\winhlp.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{4B00FA89-7C1A-41F1-AF62-C7FF0D3B96A7}
Troj/PWS-ATP also drops a non-malicious GIF image which is then opened by the default image viewer application.
