Sophos

Troj/Lydra-AD

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from May 2008 (4.29)
Protection available since 7 April 2008 04:29:48 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Lydra-AD is a Trojan for the Windows platform.

When run Troj/Lydra-AD creates the files <System>\qmgr.dll (also detected as Troj/Lydra-AD) and <System>\user.dll (detected as Troj/DwnLdr-HCE).

Troj/Lydra-AD registers itself as a system service with the name "BITS" with a description of "Background Intelligent Transfer Service" and a startup type of automatic to run the malware on startup.

Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\BITS
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_BITS

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer