Sophos

Troj/Singu-AQ

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 17 March 2007 01:05:05 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/Singu-AQ is a password-stealing Trojan for the Windows platform.

When first run, Troj/Singu-AQ copies itself to <System>\gdien32.exe and creates the following files:

<System>\lmrtend.dll
<System>\shlapi.dll

lmrtend.dll is also detected as Troj/Singu-AQ
shlapi.dll contains logged keypresses

The Trojan creates the following registry entries in order to be run automatically:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
gdien32
<System>\gdien32.exe

lmrtend.dll is installed as a BHO (browser helper object).

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer