Sophos

Troj/Dloader-UL

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2005 (3.99)
Protection available since 15 September 2005 13:16:52 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dloader-UL is a Trojan for the windows platform.

The Trojan will attempt to download and execute several files.

Troj/Dloader-UL creates the following filenames:

<System>\Rauth.exe
<System>\MAPI.dll

The Trojan creates the following registry entry so that the file Rauth.exe is run when a user logs on to Windows:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
UpDate
<System>\RAuth.exe

The Trojan attempts to inject itself into either IEXPLORE.exe or EXPLORER.exe to avoid detection.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer