Sophos

Troj/Agent-DW

Aliases
  • Backdoor.Win32.Agent.dw
  • Generic
  • Backdoor.p
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2004 (3.88)
Protection available since 20 October 2004 07:50:21 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Agent-DW is a Trojan used in DDoS attacks.

The Trojan opens multiple SMTP connections to IP addresses chosen at random within a 24-bit netmask specified by the author.

Troj/Agent-DW copies itself to the file svchost.exe in the Windows system folder then creates the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
WindowsUpdate = "C:\Windows\svchost.exe"

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
WindowsUpdate = "C:\Windows\svchost.exe"

After installing itself, the Trojan waits for up to five minutes before executing its payload.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer