Sophos

Troj/Rewindo-A

Aliases
  • Backdoor.Rewindor.11
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 14 October 2004 07:52:16 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Rewindo-A is a backdoor Trojan.

The Trojan creates the following files in the Windows folder:

Msgrt32.exe (a copy of itself)
DIjpg.dll (clean)
MSWINSCK.ocx (clean)
Winsys32.exe (also detected as Troj/Rewindo-A)
mes.rew (harmless)

Troj/Rewindo-A listens for incoming connections on a TCP port specified by the author. An attacker connecting to this port will be able to use the Trojan to take screenshots, log keypresses and steal product keys.

The Trojan creates the following registry entry:

HKLM\Software\Microsoft\CurrentVersion\Run\
WinCSRSS = "C:\Windows\Msgrt32.exe"

Troj/Rewindo-A can inform the attacker of its presence either by connecting to a preconfigured IP address and port or by submitting information to a preconfigured website via a cgi script.

The Trojan may display a fake error dialog box, with the title "Error" and a message specified by the author.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer