Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | June 2008 (4.30) |
| Protection available since | 22 April 2008 15:37:59 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Dwnldr-HCP is a worm for the Windows platform.
When W32/Dwnldr-HCP is installed the following files are created:
<System>\sft.res
<System>\sockins32.dll
The following registry entry is created to run sockins32.dll on startup:
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{66186F05-BBBB-4a39-864F-72D84615C679}
StubPath
rundll32 sockins32.dll,InitModule
The file sockins32.dll is registered as a COM object and Browser Helper Object (BHO) for Microsoft Internet Explorer, creating registry entries under:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-BBBB-4146-86FD-A722E8AB3489}
HKCR\CLSID\{66186F05-BBBB-4a39-864F-72D84615C679}
HKCR\CLSID\{FFFFFFFF-BBBB-4146-86FD-A722E8AB3489}
The following registry entry is created to run code exported by sockins32.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
WebProxy
{66186F05-BBBB-4a39-864F-72D84615C679}
The following registry entry is set:
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
iexplore.exe
0
Registry entries are created under:
HKLM\SOFTWARE\TSoft
