Sophos

Troj/Dloader-QL

Aliases
  • Downloader-ADB
  • Downloader-ADB.dll
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Protection available since 15 July 2005 21:35:40 (GMT)
Last updated 14 October 2005 08:02:12 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/Dloader-QL is a downloader Trojan for the Windows platform.

The Trojan injects code into the Windows Explorer process and uses it to download files from a preconfigured location.

The Trojan creates the following four files in the Windows system folder:
nettemp.dll
directxsvi.dll
sporder.dll
sysconfig32.ax

Nettemp.dll and directxsvi.dll are detected as Troj/Dloader-QL.
Sporder.dll is a copy of a legitimate Microsoft dll.
Sysconfig32.ax is a log file generated by the Trojan and may be safely deleted.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer