Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Protection available since | 15 July 2005 21:35:40 (GMT) |
| Last updated | 14 October 2005 08:02:12 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Dloader-QL is a downloader Trojan for the Windows platform.
The Trojan injects code into the Windows Explorer process and uses it to download files from a preconfigured location.
The Trojan creates the following four files in the Windows system folder:
nettemp.dll
directxsvi.dll
sporder.dll
sysconfig32.ax
Nettemp.dll and directxsvi.dll are detected as Troj/Dloader-QL.
Sporder.dll is a copy of a legitimate Microsoft dll.
Sysconfig32.ax is a log file generated by the Trojan and may be safely deleted.
