Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | April 2005 (3.92) |
| Protection available since | 15 February 2005 16:51:46 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Dloader-HW is a downloader Trojan for the Windows platform.
Troj/Dloader-HW downloads a configuration file from a website in the searchmiracle.com domain. The configuration file contains URLs and filenames from which the Trojan downloads further files.
Troj/Dloader-HW copies itself the the Windows system folder as a file named elite???32.exe where ??? are random characters. The Trojan ensures that the copy is run each time a user logs on by adding the following registry entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
antiware
elite???32.exe
Troj/Dloader-HW also adds several registry entries under:
HKCU\Software\LQ
