Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | December 2005 (4.00) |
| Protection available since | 9 November 2005 21:41:56 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Hazif-A is a configurable password-stealing Trojan generated by the Troj/HazifKit-A Trojan constructor kit.
Troj/Hazif-A steals Yahoo! Messenger passwords. The Trojan may also act as a backdoor server, providing a command shell to a remote user.
Stolen information may be sent by email or to another Yahoo! Messenger id.
The Trojan may copy itself to the Windows folder under another name. Typically the Trojan also copies itself to the Windows system folder as mst32init.exe.
The Trojan may be configured to disable certain features of the operating system, including System Restore, Registry Editor and Task Manager.
A fake error message may be displayed.
A registry entry of the following form may be created to run mst32init.exe on startup:
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\(<guid>)
StubPath
<System>\mst32init.exe
When Troj/Hazif-A is installed the following files are created:
<Windows>\netiu1.dll
<System>\netiu1.dll
