Sophos

Troj/Dwnldr-HCH

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2008 (4.30)
Protection available since 16 April 2008 06:46:40 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dwnldr-HCH is a Trojan for the Windows platform.

When first run,Troj/Dwnldr-HCH copies itself to C:\WINDOWS\msnmsg.exe or C:\msnmsg.exe.

Troj/Dwnldr-HCH creates C:\Program Files\Internet Explorer\msupdate.log

Troj/Dwnldr-HCH has the functionalities to:
-download files from preconfigured URL.

The following registry entry is created on startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
msnmsg
C:\WINDOWS\msnmsg.exe

or
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
msnmsg
C:\msnmsg.exe.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer