Sophos

Troj/Dropper-GS

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Protection available since 17 April 2006 20:05:35 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/Dropper-GS is a Trojan for the Windows platform.

Troj/Dropper-GS includes functionality to:
- Communicate with remote computers via http.
- Download and run code.
- Send emails.
- Redirect browser requests.

When Troj/Dropper-GS is installed it creates the file \winbrume.dll.

The file winbrume.dll is registered as a COM object and Browser Helper Object (BHO) for Microsoft Internet Explorer, creating registry entries under:

HKCR\CLSID\{196B9CB5-4C83-46F7-9B06-9672ECD9D99B}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{196B9CB5-4C83-46F7-9B06-9672ECD9D99B}

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer