Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 14 October 2004 07:52:16 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Rewindo-A is a backdoor Trojan.
The Trojan creates the following files in the Windows folder:
Msgrt32.exe (a copy of itself)
DIjpg.dll (clean)
MSWINSCK.ocx (clean)
Winsys32.exe (also detected as Troj/Rewindo-A)
mes.rew (harmless)
Troj/Rewindo-A listens for incoming connections on a TCP port specified by the author. An attacker connecting to this port will be able to use the Trojan to take screenshots, log keypresses and steal product keys.
The Trojan creates the following registry entry:
HKLM\Software\Microsoft\CurrentVersion\Run\
WinCSRSS = "C:\Windows\Msgrt32.exe"
Troj/Rewindo-A can inform the attacker of its presence either by connecting to a preconfigured IP address and port or by submitting information to a preconfigured website via a cgi script.
The Trojan may display a fake error dialog box, with the title "Error" and a message specified by the author.
