Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 27 October 2005 08:03:28 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Dloader-XF is a Trojan for the Windows platform.
When Troj/Dloader-XF is installed it creates and executes the file <System>\run.dll without notifying the user. The Trojan will also attempt to download files from a remote URL to the locations:
<System>\q4.pak
<System>\prc.exe
The file run.dll is also detected as Troj/Dloader-XF.
The following registry entry is created to run the exported code on startup using the name SecurePatch:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler
(2F212B1B-1313-1BBC-02A8-7CA23A23E13F)
SecurePatch
The following registry entry is set:
HKCU\Software\Classes\CLSID\(2F212B1B-1313-1BBC-02A8-7CA23A23E13F)\
InProcServer32
(default)
<System>\run.dll
Registry entries are created under:
HKCU\Software\Classes\CLSID\(2F212B1B-1313-1BBC-02A8-7CA23A23E13F)\
InProcServer32\
Troj/Dloader-XF will attempt to delete registry entries under:
HKLM/SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
SharedTaskScheduler
Windows Update
Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
Windows Update
