Sophos

Troj/Dloader-DT

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 6 November 2004 17:42:43 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Dloader-DT is a downloader Trojan for the Windows platform.

When first run Troj/Dloader-DT copies itself into the current folder as a file named FTPGRABER.EXE. The file has the file attributes set to hidden. In order to run on system start the Trojan creates the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
FTPGraber
FTPGRABER.EXE

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
FTPGraber
FTPGRABER.EXE

The Trojan may also create or modify the following registry entry:

HKLM\Software\Microsoft\DownloadManager\

Troj/Dloader-DT runs silently and continuously downloads a file from a remote site. The downloaded file is placed in the Windows folder with the filename MTJ.EXE.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer