Sophos

Troj/Teadoor-D

Aliases
  • Trojan-Downloader.Win32.Agent.qq
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 6 July 2005 20:48:30 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/Teadoor-D is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.

Troj/Teadoor-D includes functionality to access the internet and communicate with a remote server via HTTP.

When first run Troj/Teadoor-D copies itself to <Windows system folder>\<random name>.exe and creates the file <Windows system folder>\<random name>.dat.

The following registry entry is created to run <random name>.exe when a user logs on:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HDAudio Driver 1.0
<Windows system folder>\<random name>.exe

Troj/Teadoor-D may attempt to terminate some security related applications.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer