Antivirus and Security Software from Sophos

Sophos blogs

Troj/Torpig-AX

Aliases
  • Trojan-PSW.Win32.Sinowal.r
  • Trojan.Spy.Sinowal-25
  • Win32/TrojanDropper.Small.NEA
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 28 May 2006 16:32:49 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Torpig-AX is a multi-component keylogging Trojan for the Windows platform.

At the time of writing several samples of Troj/Torpig-AX had been seeded out as an attachment called ms56.zip.

Troj/Torpig-AX attempts to create the following files:

<Common Files>\Microsoft Shared\Web Folders\ibm00001.dll
<Common Files>\Microsoft Shared\Web Folders\ibm00001.exe
<Common Files>\Microsoft Shared\Web Folders\ibm00002.dll

Troj/Torpig-AX may also create and run components which load the dropped files.

Troj/Torpig-AX may create entries in the registry to run components of itself on restart.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer