Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 19 December 2005 04:39:08 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/AdClick-BM is a Trojan which attempts to install a stealthing component and download configuration data from a remote server to display further pop-ups.
When the application is installed the following files are created:
idemlog.exe
idesk.conf
<Windows>\system32\drivers\zpmodemnt.sys
The file zpmodemnt.sys is a stealthing component registered as a new service named "ZPMODEMSYSNTDRVNT", with a display name of "ZPMODEMSYSNTDRVNT". Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT\
Troj/AdClick-BM will create a auto-start registry entry at:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
Desktop
