Troj/Allaple-A

Category: Viruses and Spyware Protection available since:31 Aug 2006 00:00:00 (GMT)
Type: Trojan Last Updated:01 Nov 2007 17:21:20 (GMT)
Prevalence: No Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Allaple-A is a backdoor Trojan for the Windows platform.

The Trojan copies itself to numerous locations on the infected computer with randomly generated eight character filenames. These copies are all mutated to differ from the original Trojan.

Troj/Allaple-A drops numerous copies of a DLL component to the Windows system folder with randomly generated eight character filenames.

For each copy of the Trojan a registry entries such as the following are created:

HKCR\CLSID\<randomly generated CLSID>\LocalServer32
<default>
<randomly generated string>

HKCR\CLSID\<randomly generated CLSID>\LocalServer32
<default>
<Path to copy of Trojan>

The Trojan modifies existing registry entries to run the DLL components on startup. Entries are modified as follows:

HKCR\<existing CLSID>\InprocServer32
<default>
<system>\<DLL filename>

The Trojan also modifies HTML files, prepending a line such as the following to the script:

<OBJECT type="application/x-oleobject"CLASSID="CLSID:(randomly generated CLSID)"></OBJECT>

download Try Sophos products for free
Download now