Sophos

Troj/Keylog-AP

Aliases
  • Trojan-Dropper.Win32.Agent.zf
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2005 (4.00)
Protection available since 26 October 2005 08:04:21 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Keylog-AP is a keylogging Trojan for the Windows platform.

When Troj/Keylog-AP is installed it creates the file <System>\wcsys.exe.

The following registry entry is created to run wcsys.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
wcsys
<System>\wcsys.exe

Troj/Keylog-AP creates a file named wcsys.dll in the Windows system folder. This file is detected as Troj/Keylog-AC.

The Trojan may inject itself into the explorer process or register itself as a service process in order to prevent itself from being terminated.

Troj/Keylog-AP records keystrokes to the file wcsys32.dll in the Windows system folder. When this file becomes larger than 4kb, its contents are submitted to the author by email.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer