Sophos

Troj/PWSAgent-A

Aliases
  • Trojan-PSW.Win32.Agent.aa
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2005 (3.94)
Protection available since 6 May 2005 11:31:25 (GMT)
Detected by All Sophos products

Action

More Information

Troj/PWSAgent-A is a password stealing Trojan for the Windows platform.

When run Troj/PWSAgent-A copies itself to the Windows folder as winos.exe and creates the following

registry entry in order to run automatically on user logon:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
windhost.exe
<Windows folder>\winos.exe

Troj/PWSAgent-A attempts to steal confidential information including the following:

INETCOMM Server Passwords
MS IE FTP Passwords
Outlook Account Manager Passwords
Email account details for HTTP, IMAP and POP3 accounts
Cached Internet Explorer FTP passwords

The Trojan periodically sends the logged information to a script at http://bnrdrv.com.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer