Sophos

Troj/Dloadr-BLP

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Included in our products from July 2008 (4.31)
Protection available since 12 May 2008 18:26:12 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dloadr-BLP when run downloads further malware to the folder <Documents and Settings>\All Users\_qbothome.

Troj/Dloadr-BLP also creates the following registry entry so that the downloaded files autorun at startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
nwiz
"C:\documents and settings\all users\_qbothome\_qbotinj.exe" "C:\documents and settings\all users\_qbothome\_qbot.dll" /c nwiz.exe /installquiet

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer