Sophos

Troj/GrayBrd-I

Aliases
  • Backdoor.Win32.Hupigon.fv
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 14 December 2005 03:37:25 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/GrayBrd-I is a backdoor Trojan which allows a remote intruder to gain
access and control over the computer.

Troj/GrayBrd-I includes functionality to access the internet and communicate
with a remote server via HTTP.

When first run Troj/GrayBrd-I copies itself to <Program Files>\Outlook
Express\serop.exe.

The file serop.exe is registered as a new system driver service named
"virtu1qlal", with a display name of "Networok Derve H1ots" and a startup type
of automatic, so that it is started automatically during system startup.
Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\virtu1qlal\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer