Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | June 2005 (3.94) |
| Protection available since | 12 April 2005 20:37:29 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
Troj/Goldun-R is a password stealing Trojan that steals bank details and sends
them to a remote site.
Troj/Goldun-R is comprised of a dropper file with the filename pin.exe that
creates MSplg7.dll and estsprt.sys files in the Windows system folder. Sophos's anti-virus products detect estsprt.sys as Troj/Haxdor-Gen.
In order to run automatically each time a user logs on, Troj/Goldun-R sets the following registry entries:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\F8adsl\
DllName
hex(2):4d,53,70,6c,67,37,2e,64,6c,6c,00
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\F8adsl\
Startup
"MSplg7"
Troj/Goldun-R also sets a number of registry entries associated with the estsprt service under the following:
HKLM\System\CurrentControlSet\Services\estsprt\
