Sophos

Troj/Hazif-A

Aliases
  • PWSteal.Trojan
  • Trojan-PSW.Win32.Hazif.a
  • Backdoor.Win32.Bifrose.ay
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2005 (4.00)
Protection available since 9 November 2005 21:41:56 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Hazif-A is a configurable password-stealing Trojan generated by the Troj/HazifKit-A Trojan constructor kit.

Troj/Hazif-A steals Yahoo! Messenger passwords. The Trojan may also act as a backdoor server, providing a command shell to a remote user.

Stolen information may be sent by email or to another Yahoo! Messenger id.

The Trojan may copy itself to the Windows folder under another name. Typically the Trojan also copies itself to the Windows system folder as mst32init.exe.

The Trojan may be configured to disable certain features of the operating system, including System Restore, Registry Editor and Task Manager.

A fake error message may be displayed.

A registry entry of the following form may be created to run mst32init.exe on startup:

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\(<guid>)
StubPath
<System>\mst32init.exe

When Troj/Hazif-A is installed the following files are created:

<Windows>\netiu1.dll
<System>\netiu1.dll

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer