Sophos

Troj/Agent-ECR

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from May 2007 (4.17)
Protection available since 22 February 2007 08:33:20 (GMT)
Last updated 16 March 2007 07:58:07 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Agent-ECR is a Trojan for the Windows platform.

When Troj/Agent-ECR is installed the following files are created:

<Windows>\AppPatch\dldlgs.dll (Detected as Troj/Dloadr-ATV)
<Windows>\AppPatch\msimain.dll (Detected as Troj/Dropper-NP)
<System>\drivers\ksm.sys (Detected as Troj/Rootkit-BE)
<System>\drivers\soundwav.sys (Detected as Troj/Rootkit-BF)
<System>\unxxx.bat (Can be safely removed)

The following registry entry is created to run code exported by (DADE1910-86AA-D04E-4B87-28B92A3D4E99) on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
DLMonF
(DADE1910-86AA-D04E-4B87-28B92A3D4E99)

The file msimain.dll is registered as a COM object, creating registry entries under:

HKCR\CLSID\DADE1910-86AA-D04E-4B87-28B92A3D4E99

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer