Sophos

Troj/Stinx-D

Aliases
  • Backdoor.Win32.IRCBot.v
  • W32/Brepibot
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 27 October 2005 14:02:51 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Stinx-D is a backdoor Trojan for the Windows platform.

Troj/Stinx-D runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer via
IRC channels.

Troj/Stinx-D may arrive as an attachment to an email with the subject line 'Photo Approval Needed'. The filename used is 'Photo + Article.exe'.

When first run Troj/Stinx-D copies itself to <System>\cstsm.exe.

The following registry entries are created to run cstsm.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
WindowsDiskLog
cstsm.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WindowsDiskLog
cstsm.exe

Troj/Stinx-D can be instructed to delete, execute, and download and execute
files.

Troj/Stinx-D will also try and circumvent the Windows Firewall if it is
present.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer