Sophos

Troj/KeyLogg-AU

Aliases
  • Trojan-Spy.Win32.ProKeylogger.10
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from July 2006 (4.07)
Protection available since 25 May 2006 08:21:03 (GMT)
Detected by All Sophos products

Action

More Information

Troj/KeyLogg-AU is a Trojan for the Windows platform.

When first run Troj/KeyLogg-AU copies itself to:

<Windows>\@@@\start.exe
<Windows>\@@@\winlog.exe

and creates the files:

<Windows>\@@@\utils.dll - detected as Troj/KeyLogg-AU
sr.vbs - this file may be deleted

Once installed Troj/KeyLogg-AU includes functionality to:
- keylog information
- download code from the internet

Troj/KeyLogg-AU also initiates socket connections on ports 15, 53, 4575.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer