Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | August 2005 (3.96) |
| Protection available since | 1 July 2005 04:14:44 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Bdoor-IU is a backdoor Trojan for the Windows platform.
When first run Troj/Bdoor-IU copies itself to <Windows>\lsass.exe. The Trojan
will then report infection and download commands from predefined URLs.
The Trojan has the following functionality:
download & execute files
move/copy files on infected computer
send files from infected computer
search for files on infected computer
delete files from infected computer
terminate processed on infected computer
log activity on infected computer
One or more of the following registry entries will be created to run lsass.exe on
startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe <Windows>\lsass.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
LogService
<Windows>\lsass.exe
