Sophos

Troj/Banload-LK

Aliases
  • Trojan-Downloader.Win32.Banload.lk
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from March 2006 (4.03)
Protection available since 19 January 2006 09:01:13 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Banload-LK is a Trojan for the Windows platform.

Troj/Banload-LK includes functionality to download, install and run new software.

When Troj/Banload-LK is installed the following files are created:

1.bat
<Windows>\1.exe

The following registry entries are set, affecting internet security:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
FIREWALLPOLICY\

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
FIREWALLPOLICY\standardprofile\

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
FIREWALLPOLICY\standardprofile\authorizedapplications\

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
FIREWALLPOLICY\standardprofile\authorizedapplications\List\

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
FIREWALLPOLICY\standardprofile\authorizedapplications\List
<pathname of the Trojan executable>
<pathname>\<original filename>:*:enabled:p

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer