Antivirus and Security Software from Sophos

Sophos blogs

Troj/Mitglie-DQ

Aliases
  • Downloader-ADX.dll
  • Trojan-Proxy.Win32.Mitglieder.dq
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 12 September 2005 04:58:22 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Mitglie-DQ is a Trojan for the Windows platform.

When first run Troj/Mitglie-DQ copies itself to <System>\msnethlp32.exe and creates the file <System>\msnethlp32.dll.

HKCR\exefile\Shell\open\command\
"<System>\msnethlp32.exe\" -run \"%1\" %*

This will result in the Trojan being executed every time a user runs an EXE file.

Troj/Mitglie-DQ listens on a randomly-chosen port. Anyone connecting to this port will be able to download files to the infected computer and then execute them, or use the computer as a proxy via port-forwarding or the HTTP "CONNECT" command.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer