Sophos

Troj/Dropper-TG

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from March 2008 (4.27)
Protection available since 23 January 2008 19:04:16 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dropper-TG is a Trojan for the Windows platform.

When Troj/Dropper-TG is installed the following files are created:

<Favorites>\<non-ASCII characters>.url
<System>\drivers\h2pnhd.sys
<System>\drivers\ojf6n62n.sys
<System>\kt2py.dll

The file kt2py.dll is detected as Mal/Behav-010 and the file h2pnhd.sys is detected as Troj/RootCK-Gen.

The file h2pnhd.sys is registered as a new system driver service named "h2pnhd", with a display name of "h2pnhd" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\h2pnhd

The file ojf6n62n.sys is registered as a new system driver service named "ojf6n62n", with a display name of "ojf6n62n" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\ojf6n62n

Registry entries are created under:

HKLM\SOFTWARE\Microsoft\IE4

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer