Sophos

Troj/Antinny-J

Aliases
  • Trojan.Win32.KillFiles.gm
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 15 December 2004 14:48:12 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Antinny-J is a Trojan that will display a full screen image and play a sound file repeatedly.

Each time Troj/Antinny-J is run, it will attempt to delete a folder from the Program Files folder.

Troj/Antinny-J will disable the Windows Task Manager. Troj/Antinny-J is a Trojan that will display a full screen image and play a sound file repeatedly.

Each time Troj/Antinny-J is run, it will attempt to delete a folder from the Program Files folder.

Troj/Antinny-J will disable the Windows Task Manager by overwriting TASKMGR.EXE in the Windows system folder with a harmless Windows file named HH.EXE (HTML Help).

Troj/Antinny-J will copy itself to the Windows system folder as IPMIG32.EXE. In order to run automatically each time a user executes a file, Troj/Antinny-J will change the following registry entry:

HKCR\exefile\shell\open\command
(Default)
"<system>\ipmig32.exe", "%1" %*

Troj/Antinny-J will set the following registry entry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoClose
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer