Sophos

Troj/Dermon-I

Aliases
  • Trojan-Spy.Win32.Agent.jt
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Included in our products from May 2006 (4.05)
Protection available since 2 April 2006 13:50:04 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dermon-I is a password stealing Trojan for the Windows platform.

When first run Troj/Dermon-I copies itself to <System>\abrada.exe and creates
the following files:

<System>\abrada.dll - Troj/Dermon-I
<System>\abradaload.dll - Troj/Dermon-G

<System>\abrada.dll is a remote notification DLL component which sends stolen
information to a remote website.

<System>\abradaload.dll is a process injector DLL component which will attempt
to inject itself into other processes in order to stealth itself.

Troj/Dermon-I also attempts to create the following files:

<System>\abrada.ini
<System>\abrada.dat

These files may be deleted.

The following registry entries may be created to run abrada.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Abrada win32
<System>\abradaload.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Abrada win32
<System>\abradaload.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Abrada win32
<System>\abradaload.dll

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer