Sophos

Troj/Goldun-GF

Aliases
  • Trojan-Spy.Win32.Goldun.afs
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from June 2008 (4.30)
Protection available since 1 May 2008 10:02:19 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Goldun-GF is a Trojan for the Windows platform.

When Troj/Goldun-GF is installed the following files are created:

<System>\divxps.dll - Mal/HckPk-E
<System>\klite.sys - Troj/Goldun-GF

The following registry entries are created to run code exported by divxps.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\divxps
DllName
divxps.dll0

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\divxps
Startup
divxps

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\divxps
Impersonate
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer