Sophos

Troj/Maran-AJ

Aliases
  • Trojan-PSW.Win32.Maran.et
  • PWS-Maran
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
  • Monitors browser activity
Included in our products from July 2007 (4.19)
Protection available since 12 May 2007 14:16:46 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Maran-AJ is a Trojan for the Windows platform.

When run, Troj/Maran-AJ installs three files:

<windows>\avp.exe - already detected as Troj/Maran-Gen
<system>\hsvwer9.dll - included in Troj/Maran-AJ
<system>\delplem.bat - can be deleted

The file avp.exe is registered as a new system driver service named "VGADown", with a display name of "Audio Adapter" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\VGADown

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer