Antivirus and Security Software from Sophos

Sophos blogs

Troj/Dloadr-AQY

Aliases
  • Win32.Lager.dt
Category
Type
What to do
Prevalence low high

Summary

 
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 5 December 2006 07:05:09 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Dloadr-AQY is a downloader Trojan for the Windows platform.

When run Troj/Dloadr-AQY will attempt to connect to the internet and download further malware.

Troj/Dloadr-AQY will copy itself to <system>\taskdir.exe and create the following registry entry to ensure it is started automatically on login:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
taskdir
<system>\Taskdir.exe

Troj/Dloadr-AQY will also drop the following two files:
<system>\adir.dll - detected by Sophos as Troj/HideDl-B
<system>\zlbw.dll - non-malicious helper dll

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer