Sophos

Troj/Oscor-L

Aliases
  • Trojan.Win32.Agent.cdr
  • Backdoor.Win32.Agent.cdm
  • Rootkit.Win32.Agent.ky
  • TR/Small.BL
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from December 2007 (4.24)
Protection available since 18 October 2007 00:37:56 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Oscor-L is a Trojan for the Windows platform.

Troj/Oscor-L has the ability to hide itself.

Troj/Oscor-L includes functionality to access the internet and communicate with a remote server via HTTP.

Troj/Oscor-L can steal information from the following:

- Pstore credentials
- Cached passwords
- POP3 credentials
- HTTPmail credentials
- Hotmail credentials
- Auto-complete passwords
- Internet Explorer auto-complete passwords
- MSN Explorer signup credentials
- Outlook and Outlook Express credentials
- Email addresses
- Windows address book
- Key strokes
- Data based on the current window's title bar text

When first run Troj/Oscor-L copies itself to <System>\mssujl.exe and creates the following files:

<System>\drivers\tuhdn.sys - also detected as Troj/Oscor-L
<System>\inlns.dll - detected as Mal/Behav-150
<System>\knmstu.dll - also detected as Troj/Oscor-L
<System>\perfl6381.dbl - detected as Mal/Packer
<System>\thiys.tb_ - detected as Mal/Packer

The following files also dropped by Troj/Oscor-L may simply be deleted:

<System>\shunver.exe - data
<System>\snlish.cpl - text file
<System>\stiven.ax - data
<System>\uhsfe.tlb - text
<System>\wflner.tlb - text

Troj/Oscor-L sets the following registry entries, disabling the automatic startup of other software:

HKLM\SYSTEM\CurrentControlSet\Services\srservice
Start
4

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer