Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | November 2005 (3.99) |
| Protection available since | 15 September 2005 13:16:52 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Dloader-UL is a Trojan for the windows platform.
The Trojan will attempt to download and execute several files.
Troj/Dloader-UL creates the following filenames:
<System>\Rauth.exe
<System>\MAPI.dll
The Trojan creates the following registry entry so that the file Rauth.exe is run when a user logs on to Windows:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
UpDate
<System>\RAuth.exe
The Trojan attempts to inject itself into either IEXPLORE.exe or EXPLORER.exe to avoid detection.
