Sophos

Troj/Padodor-Y

Aliases
  • Trojan-Spy.Win32.Qukart.s
  • BackDoor-AXJ.dll
  • TROJ_QUKART.B
  • Trojan-Dropper.Win32.Agent.gz
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Protection available since 14 March 2005 20:49:38 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Padodor-Y is a multi-component proxy Trojan which allows unauthorised remote access to the computer via a network.

The main dropper component the file boot.sys in the root folder and a randomly-named DLL in the Windows system folder. Boot.sys drops another randomly-named DLL in the Windows system folder and the legitimate network driver ndisrd.sys in the <Windows system folder>\drivers folder.

One of the DLL components contains the proxy Trojan functionality which it attempts to inject into the explorer process.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer