Sophos

Troj/Bdoor-CR

Aliases
  • Backdoor.Win32.Robobot.f
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 24 January 2005 21:31:26 (GMT)
Last updated 27 May 2005 21:55:13 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Bdoor-CR is a backdoor Trojan for the Windows platform.

Troj/Bdoor-CR will connect to an IRC server and listen for backdoor commands. The Trojan has the capability to download and execute further files.

When first run, Troj/Bdoor-CR copies itself to the Windows system folder as LSVCHOST.EXE. In order to run automatically each time a user logs on, Troj/Bdoor-CR sets the following registry entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
.mscdsr
<Windows system folder>\lsvchost.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer