Sophos

Troj/GrayBr-CP

Aliases
  • BackDoor-AWQ
  • trojan
  • Backdoor.Win32.Hupigon.eod
  • W32/Hupigon.AFD
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2007 (4.17)
Protection available since 6 April 2007 02:08:42 (GMT)
Detected by All Sophos products

Action

More Information

Troj/GrayBr-CP is a backdoor Trojan for the Windows platform.

When Troj/GrayBr-CP is installed the following files are created:

<user>\Local Settings\Temp\??????.bat
<user>\Local Settings\Temp\<variable>\???.exe
<user>\Local Settings\Temp\<variable>\z.exe
<Windows>\Hacker.com.cn.exe
<Windows>\Temp\z.exe

where ? is a digit 0-9 and <variable> is a temporary folder name.

The file Hacker.com.cn.exe (detected separately as Troj/GrayBr-Gen) is registered as a new file system driver service named "ALGE", with a display name of "ALGE" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\ALGE

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer