Sophos

Troj/Stex-A

Aliases
  • TROJ_DLOADER.ESG
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from January 2007 (4.13)
Protection available since 10 November 2006 21:53:18 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Stex-A is a Trojan for the Windows platform.

When run, Troj/Stex-A copies itself into the system folder as iexplorer.exe. The following Registry entry is added to hook system startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
iexplorer
<Windows system folder>\iexplorer.exe

Once running, Troj/Stex-A stealths its presence. The iexplorer.exe process, Registry startup hook and iexplorer.exe file on disk are all stealthed.

Troj/Stex-A contains functionality to connect to a remote server via HTTP and download other files.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer