Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | May 2006 (4.05) |
| Protection available since | 2 April 2006 13:50:04 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Dermon-I is a password stealing Trojan for the Windows platform.
When first run Troj/Dermon-I copies itself to <System>\abrada.exe and creates
the following files:
<System>\abrada.dll - Troj/Dermon-I
<System>\abradaload.dll - Troj/Dermon-G
<System>\abrada.dll is a remote notification DLL component which sends stolen
information to a remote website.
<System>\abradaload.dll is a process injector DLL component which will attempt
to inject itself into other processes in order to stealth itself.
Troj/Dermon-I also attempts to create the following files:
<System>\abrada.ini
<System>\abrada.dat
These files may be deleted.
The following registry entries may be created to run abrada.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Abrada win32
<System>\abradaload.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Abrada win32
<System>\abradaload.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Abrada win32
<System>\abradaload.dll
