Sophos

Troj/Adbot-A

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from January 2006 (4.01)
Protection available since 27 November 2005 20:40:38 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Adbot-A is a backdoor Trojan which allows a remote intruder to gain access and control over the computer. Troj/Adbot-A refers to itself as "Ante Deus".

When first run Troj/Adbot-A copies itself to <Windows system folder>\SystemLoader.exe.

Troj/Adbot-A may set the following registry entries if instructed to do so in order to run a file on system startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Configuration Loader

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Configuration Loader

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Configuration Loader

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Configuration Loader

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
Configuration Loader

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer