Sophos

Sophos blogs

Troj/Allaple-A

Category
Type
What to do
Prevalence low high

Summary

 
Protection available since 1 September 2006 01:00:41 (GMT)
Last updated 1 November 2007 21:01:40 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Allaple-A is a backdoor Trojan for the Windows platform.

The Trojan copies itself to numerous locations on the infected computer with randomly generated eight character filenames. These copies are all mutated to differ from the original Trojan.

Troj/Allaple-A drops numerous copies of a DLL component to the Windows system folder with randomly generated eight character filenames.

For each copy of the Trojan a registry entries such as the following are created:

HKCR\CLSID\<randomly generated CLSID>\LocalServer32
<default>
<randomly generated string>

HKCR\CLSID\<randomly generated CLSID>\LocalServer32
<default>
<Path to copy of Trojan>

The Trojan modifies existing registry entries to run the DLL components on startup. Entries are modified as follows:

HKCR\<existing CLSID>\InprocServer32
<default>
<system>\<DLL filename>

The Trojan also modifies HTML files, prepending a line such as the following to the script:

<OBJECT type="application/x-oleobject"CLASSID="CLSID:(randomly generated CLSID)"></OBJECT>

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer