Sophos

Troj/Bdoor-IU

Aliases
  • Trojan-Proxy.Win32.Agent.ay
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from August 2005 (3.96)
Protection available since 1 July 2005 04:14:44 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Bdoor-IU is a backdoor Trojan for the Windows platform.

When first run Troj/Bdoor-IU copies itself to <Windows>\lsass.exe. The Trojan
will then report infection and download commands from predefined URLs.

The Trojan has the following functionality:

download & execute files
move/copy files on infected computer
send files from infected computer
search for files on infected computer
delete files from infected computer
terminate processed on infected computer
log activity on infected computer

One or more of the following registry entries will be created to run lsass.exe on
startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe <Windows>\lsass.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
LogService
<Windows>\lsass.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer