Sophos

Troj/Dloadr-LR

Aliases
  • Trojan-Downloader.Win32.Agent.mp
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from April 2006 (4.04)
Protection available since 21 February 2006 04:59:48 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dloadr-LR is a downloader and dropper Trojan for the Windows platform.

Troj/Dloadr-LR includes functionality to download, install and run new software.

When Troj/Dloadr-LR is installed the following files are created:

<System>\ffservice.exe
<System>\lservice.exe
<System>\wservice.exe

The files ffservice.exe, lservice.exe and wservice.exe are detected as Troj/Prorat-O.

The following registry entries are created to run ffservice.exe and lservice.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Windows Reg Services
<System>\ffservice.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Windows Reg Services
<System>\ffservice.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
Windows Reg Services
<System>\ffservice.exe

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{a75aed00-d7bf-11d1-9947-00c0Cf98bbc9}
StubPath
<System>\lservice.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer