Home Malware Programs Trojans Generic PWS.ta

Generic PWS.ta

Posted: September 8, 2010

Generic PWS.ta is a computer Trojan which can request other malicious files from the Internet and download them onto the system. Generic PWS.ta also has the ability to send out email messages with a built-in SMTP client engine which can send private emails directly to a recipient mail server for malicious purposes. Generic PWS.ta contains definite characteristics of an identified security risk and should be removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\108125.txt
    2 %Temp%\kfwft.dll
    3 c:\help.jpg
    4 c:\wow.jpg

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run][HKEY_CURRENT_USER\Software\WinRAR SFX]
Loading...