Sophos

Troj/Dloader-OR

Aliases
  • Trojan-Downloader.Win32.Dadobra.ax
  • Generic
  • Downloader.c
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from October 2005 (3.98)
Protection available since 13 June 2005 21:40:35 (GMT)
Last updated 7 September 2005 09:55:25 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dloader-OR is a downloader Trojan which will download, install and run new software without user's notification.

When first run Troj/Dloader-OR creates a folder called "IE" in the Windows folder and copies itself to <Windows folder>\IE\MD1.exe.

The following registry entry is created to run MD1.exe on startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
File0_0
<path of Trojan>

Registry entries are created under:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
File1
Dia Claro.htm

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer