Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | February 2006 (4.02) |
| Protection available since | 5 December 2005 13:57:47 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Certif-N is a Trojan for the Windows platform.
Troj/Certif-N steals passwords for certain Brazilian online banking applications and remote shell applications.
When first run Troj/Certif-N copies itself to <System>\_accwiz.exe.
The following registry entry is created to run _accwiz.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
_accwiz.exe
<System>\_accwiz.exe
The following registry entry is set:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion
pname
_accwiz.exe
