Sophos

Troj/Dloadr-AQY

Aliases
  • Win32.Lager.dt
Category
Type
What to do
Prevalence low high

Summary

 
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from February 2007 (4.14)
Protection available since 5 December 2006 07:05:09 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dloadr-AQY is a downloader Trojan for the Windows platform.

When run Troj/Dloadr-AQY will attempt to connect to the internet and download further malware.

Troj/Dloadr-AQY will copy itself to <system>\taskdir.exe and create the following registry entry to ensure it is started automatically on login:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
taskdir
<system>\Taskdir.exe

Troj/Dloadr-AQY will also drop the following two files:
<system>\adir.dll - detected by Sophos as Troj/HideDl-B
<system>\zlbw.dll - non-malicious helper dll

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer