Sophos

Troj/DwnLdr-FYH

Aliases
  • Win32/TrojanDownloader.Nurech.G
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from March 2007 (4.15)
Protection available since 23 January 2007 09:25:05 (GMT)
Detected by All Sophos products

Action

More Information

Troj/DwnLdr-FYH is a Trojan for the Windows platform.

Troj/DwnLdr-FYH includes functionality to;

- access the internet and communicate with a remote server via HTTP.
- download, install and run new software. Troj/DwnLdr-FYH is a Trojan for the Windows platform.

Troj/DwnLdr-FYH includes functionality to;

- access the internet and communicate with a remote server via HTTP.
- download, install and run new software.

When first run Troj/DwnLdr-FYH copies itself to <System>\ipcbt.exe and creates the file <System>\drivers\onud.dat. This file can be deleted.

The following registry entry is created to run ipcbt.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ipcbt
<System>\ipcbt.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer