Sophos

Troj/PurScan-BE

Aliases
  • Downloader-EV
  • trojan
  • Win32/TrojanDownloader.PurityScan
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from April 2007 (4.16)
Protection available since 25 February 2007 15:51:29 (GMT)
Detected by All Sophos products

Action

More Information

Troj/PurScan-BE is a dropper Trojan for the Windows platform.

Troj/PurScan-BE includes functionality to download, install and run new software.

When Troj/PurScan-BE is installed the following hidden files are created :

<User>\Local Settings\Temp\mshtml.exe
<Common Files>\Yazzle1275OinAdmin.exe
<Common Files>\Yazzle1275OinUninstaller.exe

The file mshtml.exe is detected as a component of ClickSpring adware application.

The file Yazzle1275OinUninstaller.exe is a downloader for a ClickSpring adware uninstaller. Upon execution it attempts to download and run the file <Temp>\OiUninstaller.exe

The file Yazzle1275OinAdmin.exe is also detected as Troj/PurScan-BE.

Registry entries are created under:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo

Troj/PurScan-BE provides an uninstall option which can be accessed via the Add or Remove Programs dialog in the Windows Control Panel. The software is listed as "Outerinfo".

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer