Threat Database Trojans Trojan-PSW.Win32.Certif.a

Trojan-PSW.Win32.Certif.a

By ZulaZuza in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 16
First Seen: April 12, 2013
Last Seen: April 14, 2022
OS(es) Affected: Windows

Trojan-PSW.Win32.Certif.a is a Trojan that is distributed across a local network as a malicious library. Trojan.Win32.KillWin.sp affects different gaming companies. Trojan-PSW.Win32.Certif.a creates a copy of the latest version of a malicious library to the particular folder. Trojan-PSW.Win32.Certif.a indicates the time attributes of file that has just been copied (modification time, creation time and last access) so they are the same as those for the system library. Trojan-PSW.Win32.Certif.a also indicates attributes of the malicious library as 'hidden', 'system', and 'read only'. Then, Trojan-PSW.Win32.Certif.a drops and executes an another auxiliary application. Trojan-PSW.Win32.Certif.a searches for certificates installed in the corrupted PC incorporating a private key. If Trojan-PSW.Win32.Certif.a finds any of them, it downloads them as files onto the disk. When Trojan-PSW.Win32.Certif.a finishes to work, the cybercrooks use the command 'dir' to check if any certificates had emerged.

File System Details

Trojan-PSW.Win32.Certif.a may create the following file(s):
# File Name Detections
1. wm3280.dll
2. ctime.exe
3. wm.bat
4. ec.exe

Trending

Most Viewed

Loading...