Antivirus and Security Software from Sophos

Sophos blogs

Troj/Redro-B

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Protection available since 14 November 2009 14:04:15 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/NameNotSpecfied is a Trojan for the Windows platform.

Troj/Redro-B includes functionality to:

 - run automatically
 - access the internet and communicate with a remote server via HTTP

Troj/Redro-B communicates via HTTP with the following locations:

   hbf-vip . cn


When Troj/Redro-B is installed it creates the file <System>\Ias.exe.

The file Ias.exe is registered as a new service named "Ias", with a display name
 of "MS Media Control Center". Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\Ias

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer