Skip to main content

Trojan.RegForm

Classification

Category:

Malware

Type:

Trojan

Aliases:

  • Trojan.RegForm

Summary

RegForm is trojan that steals internet access passwords and sends them to a hacker via email (through a free web-based email system). The trojan consists of two parts - a DOS part and a Windows part. The DOS part is a registration form filling application and a Windows part is a password stealing utility.

Removal

Technical Details

The trojan offers you to become a tester and promises to grant a free access to Internet in Moscow. When the trojan is executed it shows the following text screen (in Russian):

Dear Sirs, The Softnet Euro company provides you with a free dial-up access to Internet via Moscow telephone lines. This is done to test the quality of phone lines and certain remote access servers. We are inviting you to take part in testing. To get a free access you need to fill in registration form (see below) and to specify your login and password that you will use. This information will be saved to REG_FORM.DAT file in encrypted format. You will have to send this file to our automatic mail robot to the following address: euro.softnet@usa.net. After that your password will be enabled and the Internet access phone numbers will be sent to you. This free service is provided from 13:00 till 23:00 during working days only. If you want to get a commercial Internet access please call (095) 911-3535. Press any key

Then the trojan asks to fill in registration form (the funny thing is that it doesn't even ask for user's email address to send back Internet access phone numbers):

Please fill in the registration form. Your last and first names and initials: Operating system you are using: Modem type you are using: Your login to access our system: Your private password: Please re-enter your password: Registration is complete. Your information has been saved. Please send the created file to the above specified email address. Press any key

After doing the above described registration the trojan extracts a small Windows program from its body and from now on this Windows part of a trojan will store all logins and passwords the user inputs to REG_FORM.DAT. If the user finally sends this file to the specified email address a hacker gets all the logins and passwords typed by the user.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.