Sophos

W32/Dwnldr-HCP

Aliases
  • W32/Downloader.gen9
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2008 (4.30)
Protection available since 22 April 2008 15:37:59 (GMT)
Detected by All Sophos products

Action

More Information

W32/Dwnldr-HCP is a worm for the Windows platform.

When W32/Dwnldr-HCP is installed the following files are created:

<System>\sft.res
<System>\sockins32.dll

The following registry entry is created to run sockins32.dll on startup:

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{66186F05-BBBB-4a39-864F-72D84615C679}
StubPath
rundll32 sockins32.dll,InitModule

The file sockins32.dll is registered as a COM object and Browser Helper Object (BHO) for Microsoft Internet Explorer, creating registry entries under:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-BBBB-4146-86FD-A722E8AB3489}
HKCR\CLSID\{66186F05-BBBB-4a39-864F-72D84615C679}
HKCR\CLSID\{FFFFFFFF-BBBB-4146-86FD-A722E8AB3489}

The following registry entry is created to run code exported by sockins32.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
WebProxy
{66186F05-BBBB-4a39-864F-72D84615C679}

The following registry entry is set:

HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
iexplore.exe
0

Registry entries are created under:

HKLM\SOFTWARE\TSoft

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer