Sophos

Troj/Kbot-A

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
  • Opens links to websites
Included in our products from July 2008 (4.31)
Protection available since 7 May 2008 10:24:11 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Kbot-A is a Trojan for the windows platform.

When first run Troj/Kbot-A copies itself to <System>\Spcvls.exe and creates the following files:

<System>\Spcvls.dll
<System>\Spcvls.ini
<System>\Spcvls.sys

The file Spcvls.dll is detected as Mal/Behav-010 and the file Spcvls.sys is detected as Troj/Kbot-A.

The file Spcvls.exe is registered as a new system service named "Spcvlsvs", with a display name of "Spcvl Srv" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\Spcvlsvs

The file Spcvls.sys is registered as a new system driver service named "SpcvlsvsDrv", with a display name of "SpcvlsvsDrv". Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\SpcvlsvsDrv

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer