Sophos

Troj/ExpHook-A

Aliases
  • Trojan-PSW.Win32.Agent.bl
  • TSPY_SIPWEB.A
  • PWS-ExpHook
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2005 (3.99)
Protection available since 11 August 2005 21:04:16 (GMT)
Last updated 9 September 2005 17:19:32 (GMT)
Detected by All Sophos products

Action

More Information

Troj/ExpHook-A is a password stealing Trojan for the Windows platform.

Troj/ExpHook-A includes functionality to access the internet and communicate
with a remote server via HTTP.

When first run Troj/ExpHook-A copies itself to <System>\dlhost.exe.

The following registry entry is created to run dlhost.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
dlhost
<System>\dlhost.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer