Sophos

Troj/Dloader-WA

Aliases
  • Downloader-AFY
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2005 (3.99)
Protection available since 12 October 2005 22:50:45 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dloader-WA is a downloading Trojan for the Windows platform.

Troj/Dloader-WA will download and execute files from predefined URLs to the following locations:

C:\windows\sstray.exe
C:\windows\svhost.exe
C:\windows\lcass.exe
C:\windows\winlog.exe
C:\windows\stat
C:\windows\tskmgr.exe

Troj/Dloader-WA will copy itself to the Windows folder and create the following registry entry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
klop
<Windows>\<original name of executable>

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer