Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 23 September 2005 22:27:53 (GMT) |
| Last updated | 11 October 2005 11:01:19 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Lecna-D is a backdoor Trojan for the Windows platform.
Troj/Lecna-D includes functionality to access the internet and communicate with a remote server via HTTP.
When first run Troj/Lecna-D copies itself to <Windows system folder>\WINDOWSUPDATE.EXE and creates the file <Windows system folder>\drivers\USBTest.sys.
The file USBTest.sys is detected by Sophos's anti-virus products as Troj/RKPort-Fam.
The file USBTest.sys is registered as a new system driver service named "USBTest", with a display name of "USBTest". Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\USBTest\
Troj/Lecna-D downloads a file from a preconfigured URL to netscv.exe in the Windows folder and executes it.
The Trojan reduces the security on certain network shares by setting the following registry entry:
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\
forceguest
0
Troj/Lecna-D also creates registry entries for its own use under:
HKLM\SOFTWARE\Microsoft\CurrentNetInf\
