Sophos

Troj/OptixP-O

Aliases
  • Backdoor.Win32.Optix.o
  • BackDoor-ACH
  • Backdoor.Optix
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 25 November 2005 00:59:19 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/OptixP-O is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.

When first run Troj/OptixP-O copies itself to <System>\msiexec16.exe and creates the following files:

<Windows>\198.125
<Windows>\686.368
<System>\ldrmsvbvm06.dll
<System>\msvbvm06.dll

The files ldrmsvbvm06.dll and <System>\msvbvm06.dll are detected as Troj/Optix-PRO.

The following line is added to the [windows] section of Win.ini to run msiexec16.exe on startup:

run = <System>\msiexec16.exe

The pathname of msiexec16.exe is appended to the 'shell=' line in the [boot] section of System.ini, so that it is run on startup.

The following registry entries are set, affecting internet security:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\EnableAutodial

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnableAutodial

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer