Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | May 2007 (4.17) |
| Protection available since | 17 March 2007 01:05:05 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Singu-AQ is a password-stealing Trojan for the Windows platform.
When first run, Troj/Singu-AQ copies itself to <System>\gdien32.exe and creates the following files:
<System>\lmrtend.dll
<System>\shlapi.dll
lmrtend.dll is also detected as Troj/Singu-AQ
shlapi.dll contains logged keypresses
The Trojan creates the following registry entries in order to be run automatically:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
gdien32
<System>\gdien32.exe
lmrtend.dll is installed as a BHO (browser helper object).
