Sophos

Troj/Lurk-A

Aliases
  • ADSPY/Lurker.A
  • Trojan.Win32.Agent.jhm
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from May 2008 (4.29)
Protection available since 3 April 2008 19:38:24 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Lurk-A is a Trojan for the Windows platform.

When first run Troj/Lurk-A copies itself to <System>\wmpdriver.exe and creates the following registry entries to run wmpdriver.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
wmpdriver
<System>\wmpdriver.exe

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3AF58793-9D53-3495-2A92-94D1B4A0E848}
StubPath
<System>\wmpdriver.exe

Troj/Lurk-A injects it's code into a hiddent instance of Microsoft Internet Explorer.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer