Sophos

Troj/Oscor-M

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from April 2008 (4.29)
Protection available since 27 March 2008 23:24:09 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Oscor-M is a backdoor Trojan for the Windows platform which allows a remote intruder to gain access and control over the computer.

Troj/Oscor-M creates a hidden instance of Internet Explorer to communicate with the remote server via http POST messages.

When Troj/Oscor-M is run, the following files are created:

<System>\wsnpoem\audio.dll - data file, can be deleted
<System>\wsnpoem\video.dll - data file, can be deleted
<Temp>\back.exe - detected as Troj/Oscor-M
<Temp>\fff.exe - detected as Troj/Oscor-M
<System>\cryptonet.dll - detected as Troj/Oscor-M

The following registry entry is created to run code exported by cryptonet.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptonet
DllName
cryptonet.dll

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer