Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 20 December 2004 12:50:30 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Loony-J is a Windows backdoor Trojan which allows unauthorised remote access to the infected computer via IRC channels.
When run the Trojan moves itself to the Windows system folder as windll32.exe and creates the following registry entry so as to run itself on computer logon:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
windll32 Driver
windll32.exe
Troj/Loony-J may also display a fake error message box with the title "Error-348" and the message text "Runtime Link not found".
Once installed, Troj/Loony-J will attempt to setup a SOCKS4 server, steal CD keys and download and run files from the internet when instructed to do so by a remote attacker.
