Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 11 June 2008 23:30:01 (GMT) |
| Last updated | 13 June 2008 17:32:01 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
When first run Troj/Dloadr-BMH creates one or more of the following files:
<Temp>\rad<random hexadecimal digits>.vbs - also detected as Troj/Dloadr-BMH
<Temp>\rad<random hexadecimal digits>.htm - can be safely deleted.
Troj/Dloadr-BMH creates the following registry entry to start itself:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
idmssn
Wscript <Temp>\rad<random hexadecimal digits>.vbs
