Sophos

Troj/Agent-ZD

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from February 2006 (4.02)
Protection available since 6 December 2005 06:33:14 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Agent-ZD is a Trojan for the Windows platform.

When Troj/Agent-ZD is installed the following files are created:

<System>\doser.exe
<System>\ssldr32.dll

The file doser.exe is detected as Troj/Agent-PE.

The following registry entries are created to run code exported by ssldr32.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssldr
Impersonate
0

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssldr
DLLName
ssldr32.dll

The Trojan allows remote attackers the ability to route internet traffic through the infected computer.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer