Sophos

Troj/Shpiel-A

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 30 December 2005 16:40:37 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Shpiel-A is a backdoor Trojan for the Windows platform.

When first run Troj/Shpiel-A copies itself to the Windows folder with a name chosen randomly from the following list :

'msnupdate.exe'
'winfog.exe'
'winsys.exe'
'lsass1.exe'
'lovcx.exe'
'winsress.exe'
'winlog.exe'
'winsock.exe'
'saveruser.exe'
'winbackup.exe'

The following registry entry is created to run Troj/Shpiel-A on startup :

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Hutley-Spieluhr
<Windows system folder>\<filename>

Troj/Shpiel-A creates an FTP server that listens by default on port 25 (normally reserved for SMTP) to enable uploading of files which can then be executed remotely using the server component of the Trojan.

Troj/Shpiel-A stores its configuration information such as FTP port number and logon credentials under the following registry entry :

HKLM\SOFTWARE\MsnSpieluhr\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer