Troj/Boa-A

Discussion in 'malware problems & news' started by Technodrome, May 13, 2003.

Thread Status:
Not open for further replies.
  1. Technodrome

    Technodrome Security Expert

    Joined:
    Feb 13, 2002
    Posts:
    2,140
    Location:
    New York
    Aliases
    W32.Boa.Worm

    At the time of writing Sophos has received just one report of this Trojan from the wild.


    Troj/Boa-A is a keylogging Trojan. The Trojan monitors keypresses and other system activity and periodically sends an email to the attacker containing a log of the actions monitored on the victim's machine.

    When Troj/Boa-A is first executed a copy will be created in the System folder with the filename msnet.exe and the following two registry files will be created so that the Trojan is run when Windows starts up:

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\msnet
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\msnet


    more: http://www.sophos.com



    Technodrome
     
Thread Status:
Not open for further replies.