Sophos

Sophos blogs

Troj/PWS-BFH

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 3 November 2009 11:23:36 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/PWS-BFH is a Trojan for the Windows platform.

When Troj/PWS-BFH is run the following files are created:

<Windows>\Web\printers\images\harce.dll
<Windows>\Web\printers\images\harce.exe

The file harce.dll is registered as a COM object and shell extension, creating registry entries under:

HKCR\CLSID\{1FB3B422-7793-455A-8802-660853A9D102}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer