Sophos

Troj/Dermon-G

Aliases
  • BackDoor-CIU
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from April 2006 (4.04)
Protection available since 5 March 2006 17:20:27 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dermon-G is a password stealing Trojan for the Windows platform.

When first run Troj/Dermon-G copies itself to <System>\abrada.exe and creates the following files:

<System>\abrada.dll
<System>\abradaload.dll

<System>\abrada.dll is a remote notification DLL component which sends stolen information to a remote website.

<System>\abradaload.dll is a process injector DLL component which will attempt to inject itself into other processes in order to stealth itself.

Troj/Dermon-G also attempts to create the following files:

<System>\abrada.ini
<System>\abrada.dat

These files may be deleted.

The following registry entries are created to run abrada.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Abrada win32
<System>\abradaload.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Abrada win32
<System>\abradaload.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Abrada win32
<System>\abradaload.dll

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer