Sophos

Troj/Keylog-AN

Aliases
  • Trojan-Spy.Win32.Agent.ew
  • PWS-Reox
  • PWSteal.Reoxtan
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2005 (3.99)
Protection available since 24 September 2005 14:57:39 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Keylog-AN is a password stealing Trojan which attempts to steal confidential information and send it to a remote location.

Troj/Keylog-AN includes functionality to steal confidential information including user account information, dial-up information, and passwords from Outlook Express and other email related applications.

When first run Troj/Keylog-AN copies itself to <Windows system folder>\service\explorer.exe and creates the file <Windows system folder>\service\dllp.txt. It may also create the following files:

<Windows system folder>\service\dllw.txt
<Windows system folder>\service\dlls.txt
<Windows system folder>\service\dll<random number>.txt
<Windows system folder>\\service\reoxconf1.sp
<Windows system folder>\service\reoxconf.sp
<Windows system folder>\service\reoxconf1.sam
<Windows system folder>\service\reoxconf.sam
<Windows system folder>\service\reoxconf.dl
<Windows system folder>\service\scr<random number>.html

These files are not malicious and may be safely deleted.

The following registry entry may be created to run explorer.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
<number>
<Windows system folder>\service\explorer.exe

Troj/Keylog-AN may disable Windows Firewall and may attempt to automatically close security warning messages displayed by common anti-virus and security related applications.

The following registry entries may be set, affecting internet security:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile\

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile
DisableNotifications
1

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile
EnableFirewall
0

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile
DoNotAllowExceptions
0

Troj/Keylog-AN may modify the HOSTS file which maps the URLs of selected websites to its own IP addresses, in order to affect redirection and therefore hijack browsing.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer