Home Malware Programs Trojans Trojan-PSW.Win32.Certif.a

Trojan-PSW.Win32.Certif.a

Posted: April 12, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 37
First Seen: April 12, 2013
Last Seen: April 14, 2022
OS(es) Affected: Windows

Trojan-PSW.Win32.Certif.a is a Trojan that circulates across a local network as a malicious library. Trojan.Win32.KillWin.sp attacks numerous gaming companies. Trojan-PSW.Win32.Certif.a copies the latest version of a malicious library to the specific folder. Trojan-PSW.Win32.Certif.a indicates the time attributes of file that has just been copied (modification time, creation time and last access) so they are the same as those for the system library. Trojan-PSW.Win32.Certif.a also indicates attributes of the malicious library as 'hidden', 'system', and 'read only'. After that, Trojan-PSW.Win32.Certif.a downloads and executes an another auxiliary program. Trojan-PSW.Win32.Certif.a looks for certificates installed in the affected computer system involving a private key. If Trojan-PSW.Win32.Certif.a finds any of them, it downloads them as files onto the disk. When Trojan-PSW.Win32.Certif.a stops working, the attackers uses the command 'dir' to check if any certificates had occurred.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



wm.bat File name: wm.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file
ctime.exe File name: ctime.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
wm3280.dll File name: wm3280.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
ec.exe File name: ec.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Loading...