Sophos

Troj/DwnLdr-HDL

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2008 (4.31)
Protection available since 15 May 2008 05:49:26 (GMT)
Detected by All Sophos products

Action

More Information

Troj/DwnLdr-HDL is a Trojan for the Windows platform.

When run Troj/DwnLdr-HDL creates the file <System>\wmcstd32.dll (also detected as Troj/DwnLdr-HDL ) and registers it as a Browser Helper Object (BHO), creating registry entries under:

HKCR\CLSID\{97182737-4655-64C7-8730-2921803F7A9D}\InProcServer32
(default)
<System>\wmcstd32.dll

HKCR\CLSID\{97182737-4655-64C7-8730-2921803F7A9D}\InProcServer32
ThreadingModel
Apartment

The following registry entries are set:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{97182737-4655-64C7-8730-2921803F7A9D}
(default)
Explorer

HKCU\Software\Microsoft\Internet Explorer\Main
Enable Browser Extensions
yes

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer