Sophos

Troj/Loony-J

Aliases
  • Backdoor.Win32.Hackarmy.gen
  • W32/Spybot.worm.gen.b
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 20 December 2004 12:50:30 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Loony-J is a Windows backdoor Trojan which allows unauthorised remote access to the infected computer via IRC channels.

When run the Trojan moves itself to the Windows system folder as windll32.exe and creates the following registry entry so as to run itself on computer logon:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
windll32 Driver
windll32.exe

Troj/Loony-J may also display a fake error message box with the title "Error-348" and the message text "Runtime Link not found".

Once installed, Troj/Loony-J will attempt to setup a SOCKS4 server, steal CD keys and download and run files from the internet when instructed to do so by a remote attacker.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer