Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | January 2008 (4.25) |
| Protection available since | 19 November 2007 04:39:42 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/StraDr-A is a Trojan for the Windows platform.
Troj/StraDr-A includes functionality to access the internet and communicate with a remote server via HTTP.
When Troj/StraDr-A is installed the following files are created:
<Current Folder>l\fash.exe
<System>\e1.dll
<System>\keymnetc.exe
<System>\ntdlcdfv.dll
<System>\rnr2msft.dll
<System>\sccbxenr.exe
The files fash.exe and sccbxenr.exe are also detected as Troj/StraDr-A. The files e1.dll, keymnetc.exe, ntdlcdfv.dll and rnr2msft.dll are detected as W32/Strati-Gen.
The following registry entry is created to run sccbxenr.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
sccbxenr
<System>\sccbxenr.exe
