Sophos

Sophos blogs

Troj/Bdoor-DIJ

Aliases
  • WORM_SIWEOL.A
  • Backdoor-DIJ
  • Worm.Win32.RJump.a
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Opens links to websites
Protection available since 30 June 2006 20:55:29 (GMT)
Last updated 18 October 2006 22:51:52 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Bdoor-DIJ is a proxy Trojan for the Windows platform.

The Trojan installs a Socks4 proxy server and contacts a remote site to report the infection and availability of the proxy server.

When first run the Trojan copies itself to the Windows folder as RavMonE.exe and sets the following registry entry in order to run each time a user logs on:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
RavAV
"<Windows>\RavMonE.exe"

Troj/Bdoor-DIJ may attempt to copy the following files to mapped drives:

RavMonE.exe
autorun.inf
msvcr71.dll

RavMonE.exe is a copy of Troj/Bdoor-DIJ
Msvcr71.dll is a clean DLL file.
Autorun.inf attempts to launch the Trojan when the mapped drive is accessed.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer