Main Menu
Home
Bookmark
Contact Us



 
Trojan.PSW.Phreake Viruses Information

Name: Trojan.PSW.Phreake
Category: Viruses
Description: Details
Trojan.PSW.Phreaker

This program belongs to the family of password stealing Trojans (PSW).
When run, the Trojan installs itself to the Windows system directory with the KERNEL32.EXE name and registers this file in the system registry auto-run section:
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun kernel32 = kernel32.exe
The Trojan can also drop an additional DLL library KERN32.DLL. The Trojan then registers itself in the system as a hidden aplication (service), the Trojan process then is not visible in the task list.
When active in the system, the Trojan periodically sends e-mail messages to its host (hacker's e-mail address - this address also is optional). The message contains the following: computer information (owner, Internet address, etc); RAS and ICQ information; cached passwords (login name and password); as well as text strings that are entered by a user during a Windows session.
The Trojan can be managed by a special script (set of commands) that is placed on a Web page (i.e., this Trojan has "backdoor" ability), but this page is off.



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Email-Worm.Win32.Monikey.
Trojan.Win32.GhostSp
IRC-Worm.Tetri
Macro.Word.Toms
Rogue.180
VM Famil
Macro.Word.Chak
I-Worm.Sobig.b (aka Palyh
Carnage.67
Attack.358


 


© 2006-2008 spyware32.com - Privacy Policy