Sophos

Troj/Dloadr-AZK

Aliases
  • Trojan-Downloader.Win32.Banload.cil
  • Win32/TrojanDownloader.Nurech.BG
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2007 (4.19)
Protection available since 7 June 2007 19:28:58 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dloadr-AZK is a downloading Trojan for the Windows platform.

Troj/Dloadr-AZK includes functionality to access the internet and communicate with a remote server via HTTP.

When first run Troj/Dloadr-AZK copies itself to <System>\ggrrgg.exe and creates the file <System>\drivers\fee.

The following registry entry is created to run ggrrgg.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
gtydf
ggrrgg.exe

The Trojan attempts to terminate the following processes:

zlclient.exe
outpost.exe
kpf4ss.exe
kavpf.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer