Troj/BushTro122

Category: Viruses and Spyware Protection available since:16 Nov 2001 00:00:00 (GMT)
Type: Trojan Last Updated:16 Nov 2001 00:00:00 (GMT)
Prevalence: No Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/BushTro122 is a backdoor Trojan which will run in the background as a server process, allowing a remote user (using a client program) to gain access and control over the computer.

It copies itself to the Windows directory as SERVER.EXE and to the Windows System32 directory as system.exe. It also creates the registry keys

HKLM\Software\Microsoft\Windows\CurrentVersion
\RunServices\System32 = Windows System32\system.exe

and

HKCU\Software\Microsoft\Windows\CurrentVersion
\Run\SERVER.EXE = Windows\SERVER.EXE

This causes both copies of the server process to be run automatically each time the computer is restarted. Troj/BushTro122 will also attempt to notify the remote hacker when the affected computer is accessible.

download Try Sophos products for free
Download now