Sophos

Troj/Insor-B

Aliases
  • Trojan-Dropper.Win32.Small.aay
  • Downloader-ACG
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 28 June 2005 08:07:25 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Insor-B is a downloader and proxy Trojan.

When run the Trojan drops iedld32.dll into the Windows system folder and loads it.

Troj/Insor-B can be given a command to download and run an executable or provide a proxy connection on a random port. Troj/Insor-B is a downloader and proxy Trojan.

When run the Trojan drops iedld32.dll into the Windows system folder and loads it.

When there is an active internet connection Troj/Insor-B notifies a remote server that it is active and waits for a command.

Troj/Insor-B can be given a command to download and run an executable or provide a proxy connection on a random port.

Troj/Insor-B will create the following registry entries so as to auto-load:

HKCR\CLSID\(114C670C-C510-4F49-B431-4B812F50BA7B)\InprocServer32
(default)
"<System>\iedld32.dll"

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer