Sophos

Troj/Pushdo-B

Aliases
  • Trojan-Downloader.Win32.Agent.deu
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Included in our products from November 2007 (4.23)
Protection available since 12 September 2007 00:50:25 (GMT)
Last updated 12 September 2007 03:06:54 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Pushdo-B is a Trojan for the Windows platform.

When Troj/Pushdo-B is installed it drops and runs a further file in memory, detected as Troj/Pushu-B or Mal/Basine-C. This will then drop further files, using filenames from the following:

<Windows>\system32\drivers\ip6fw.sys
<Windows>\system32\drivers\netdtect.sys
<System>\drivers\runtime.sys
<System>\drivers\secdrv.sys

These files are used to provide stealthing for the Trojan, and are detected as Troj/NTRootK-BY and Troj/Agent-FVT.

The dropped file in memory will also usually attempt to inject further code into Internet Explorer.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer