Home Malware Programs Trojans PWS:Win32/Fotip.A

PWS:Win32/Fotip.A

Posted: July 3, 2013

Threat Metric

Threat Level: 8/10
Infected PCs: 73
First Seen: July 3, 2013
OS(es) Affected: Windows

PWS:Win32/Fotip.A is a password-stealing Trojan that gathers a victim's passwords for email and IM programs and passwords stored in Internet browsers. PWS:Win32/Fotip.A then transmits these passwords to a remote attacker. PWS:Win32/Fotip.A strives to steal the affected computer user's passwords. After PWS:Win32/Fotip.A has been removed, target computer users should change their passwords. When installed on the compromised PC, PWS:Win32/Fotip.A makes system changes by downloading potentially malicious files and making registry modifications. PWS:Win32/Fotip.A disables the Windows Firewall, and transmits the passwords stolen by the numerous programs to a remote FTP website.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



sad.vbs File name: sad.vbs
Mime Type: unknown/vbs
Group: Malware file
aatd.bat File name: aatd.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file
bms.klm File name: bms.klm
Mime Type: unknown/klm
Group: Malware file
cond.reg File name: cond.reg
Mime Type: unknown/reg
Group: Malware file
dd.vbs File name: dd.vbs
Mime Type: unknown/vbs
Group: Malware file
icd.bat File name: icd.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file
ictd.bat File name: ictd.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file
ied.bat File name: ied.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file
iewed.bat File name: iewed.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file
image.exe File name: image.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
keeprun.ini File name: keeprun.ini
Mime Type: unknown/ini
Group: Malware file
msnd.exe File name: msnd.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
picture viewer.exe File name: picture viewer.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
pid.pdf File name: pid.pdf
Mime Type: unknown/pdf
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run stat2 = "aatd.bat"
Loading...