Sophos

Troj/Dloadr-AWD

Aliases
  • Trojan-Downloader.Win32.Small.ase
  • Generic
  • Downloader.ad
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 27 March 2007 22:02:58 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Dloadr-AWD is a downloading Trojan for the Windows platform.

The following registry entry is set, affecting internet security:

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
1A10
0

Troj/Dloadr-AWD may create the following files:

stisvsq1.exe
svshost1.exe
msqdevl1.exe
lssas1.exe
mservice1.exe
iau1.exe

The following registry entries may be set, causing files to run on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Internet Connection Wizard
stisvsq1.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Games Acceleration
svshost1.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Internet Mail and News
msqdevl1.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Management Console
lssas1.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Multimedia extensions
mservice1.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Office Quick Launcher
iau1.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Internet Connection Wizard
stisvsq1.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Games Acceleration
svshost1.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Internet Mail and News
msqdevl1.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Management Console
lssas1.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Multimedia extensions
mservice1.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer