Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | July 2008 (4.31) |
| Protection available since | 12 May 2008 18:26:12 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Dloadr-BLP when run downloads further malware to the folder <Documents and Settings>\All Users\_qbothome.
Troj/Dloadr-BLP also creates the following registry entry so that the downloaded files autorun at startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
nwiz
"C:\documents and settings\all users\_qbothome\_qbotinj.exe" "C:\documents and settings\all users\_qbothome\_qbot.dll" /c nwiz.exe /installquiet
