Sophos

Troj/Crypter-C

Aliases
  • TrojanDownloader.Win32.Crypter
  • SysCenter
  • Win32/TrojanDownloader.Crypter.A
Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from May 2004 (3.81)
Protection available since 26 March 2004 12:15:37 (GMT)
Detected by All Sophos products

Action

Please follow the instructions for removing Trojans.

You will also need to edit the following registry entry, if it is present. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

and remove any reference to any file you deleted.

Close the registry editor.

Editing Win.ini

At the taskbar, click Start|Run and type Sysedit. Bring Win.ini to the front. In the [windows] section, search for a line beginning with 'Run=' and delete any references to the files you removed. Delete only that reference, not any other text.

Reboot your computer.

More Information

Troj/Crypter-C is a downloader Trojan which runs continuously in the background and periodically tries to download files from a remote location.

When first run the Trojan copies itself to the Windows System folder using a randomly selected filename. Filenames used by the Trojan include: audiodrv.exe, audioinf.exe, bluecol.exe, cmdcon.exe, diskinf.exe, dllreg.exe, enhance32.exe, infdisk.exe, kbddrv32.exe, kbdrvinf.exe, main16.exe, main32.exe, mousedrv.exe, mswavedll.exe, msurl32.exe, netdll32.exe, netdllex.exe, p4mx4.exe, m32info.exe, pwr32ctr.exe, pwr32crtl.exe, sd32info.exe, vid32cntl.exe and vidcntl.exe.

The Trojan adds its pathname to a new sub-key of the following registry entry to run itself on startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\

The name of the new sub-key matches the filename of the Trojan executable, excluding the extension.

The Trojan also runs itself on startup by adding its pathname to a new run= line in the [Windows] section of <WINDOWS>\WIN.INI.

The following registry entry is also created:

HKCU\Software\Microsoft\Windows\CurrentVersion\uninstall\
<filename>\UninstallString = %SYSTEM%\<filename>.exe <key>

Temporary files may be created in the Windows TEMP folder with filenames matching that of the Trojan executable, but without an extension.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer