Sophos

Troj/Opnis-D

Aliases
  • Trojan.Win32.Opnis.d
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 15 May 2006 04:57:48 (GMT)
Last updated 24 May 2006 13:59:23 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Opnis-D is a Trojan for the Windows platform.

When run, Troj/Opnis-D creates the following files:

<Temp>/~dr?.tmp
<System>\ieen445F8764.dll
<System>\ntms445F8764.dll
<System>\olea445F8764.exe
<System>\plgwiz32.dll
<System>\usrs445F8764.dll

The "~dr?.tmp" file is a rootkit that provides stealing ability for the Trojan.

The Trojan interferes with the following processes:

ccapp.exe
firefox.exe
iexplore.exe
mpftray.exe
opera.exe
outpost.exe
services.exe
smc.exe
svchost.exe
zapro.exe
zlclient.exe

Troj/Opnis-D allows backdoor access to the infected computer.

The Trojan has the ability to communicate with a remote server via HTTP.

Registry entries are created under:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\plgwiz32

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_<COMPUTER NAME><DIGITS>\

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
"ieen445F8764.dll usrs445F8764.dll"

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer