Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | December 2005 (4.00) |
| Protection available since | 26 October 2005 08:04:21 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Keylog-AP is a keylogging Trojan for the Windows platform.
When Troj/Keylog-AP is installed it creates the file <System>\wcsys.exe.
The following registry entry is created to run wcsys.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
wcsys
<System>\wcsys.exe
Troj/Keylog-AP creates a file named wcsys.dll in the Windows system folder. This file is detected as Troj/Keylog-AC.
The Trojan may inject itself into the explorer process or register itself as a service process in order to prevent itself from being terminated.
Troj/Keylog-AP records keystrokes to the file wcsys32.dll in the Windows system folder. When this file becomes larger than 4kb, its contents are submitted to the author by email.
