Sophos

Troj/AdClick-AG

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from March 2005 (3.91)
Protection available since 14 January 2005 09:14:47 (GMT)
Detected by All Sophos products

Action

More Information

Troj/AdClick-AG is a Trojan for the Windows platform.

Troj/AdClick-AG will repeatedly attempt to connect to a remote website.

Troj/AdClick-AG will copy itself to the Windows folder as LSASS.EXE, SVCHOST.EXE or CSRSS.EXE. In order to run automatically each time a user logs in, the Trojan will set one of the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Update
%WINDOWS%\<filename> /i

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Runner
%WINDOWS%\<filename> /i

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
System Process
%WINDOWS%\<filename> /i

where <filename> is either lsass.exe, svchost.exe or csrss.exe.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer