Sophos

Troj/Vixup-BZ

Aliases
  • Trojan-Downloader.Win32.Tibs.ir
  • Win32/TrojanDownloader.Small.AWA
  • Trojan.Galapoper.A
  • TROJ_TIBS.OS
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from February 2007 (4.14)
Protection available since 21 November 2006 16:57:38 (GMT)
Last updated 12 December 2006 13:41:57 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Vixup-BZ is a Trojan for the Windows platform.

Troj/Vixup-BZ includes functionality to download and run further executable code. Troj/Vixup-BZ is a Trojan for the Windows platform.

Troj/Vixup-BZ includes functionality to download and run further executable code.

When first run Troj/Vixup-BZ copies itself to <System>\kernels8.exe and may download a file to <System>\dlh9jkdq8.exe.

The following registry entry is created to run kernels8.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
System
<System>\kernels8.exe

The following registry entry is set, disabling the Windows task manager (taskmgr):

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer