Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | January 2006 (4.01) |
| Protection available since | 27 November 2005 20:40:38 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Adbot-A is a backdoor Trojan which allows a remote intruder to gain access and control over the computer. Troj/Adbot-A refers to itself as "Ante Deus".
When first run Troj/Adbot-A copies itself to <Windows system folder>\SystemLoader.exe.
Troj/Adbot-A may set the following registry entries if instructed to do so in order to run a file on system startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Configuration Loader
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Configuration Loader
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Configuration Loader
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Configuration Loader
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
Configuration Loader
