Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 26 July 2005 20:47:08 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Tofger-AP is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.
The Trojan is able to log keypresses. Stolen information is sent to a remote user by email.
When Troj/Tofger-AP is installed the following files are created:
<Windows>\adrt32.dll
<Windows>\svchost.exe
<Windows>\winili.ini
The files adrt32.dll and svchost.exe are also detected as Troj/Tofger-AP. The file winili.ini is used to store stolen information.
The following registry entry is created to run svchost.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Perfomance Settings
<Windows>\svchost.exe
Registry entries are created under:
HKLM\SOFTWARE\Microsoft\Rotym\
