Sophos

Troj/Dloadr-UY

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2006 (4.06)
Protection available since 9 May 2006 05:41:52 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dloadr-UY is a downloader Trojan for the Windows platform.

When first run Troj/Dloadr-UY copies itself to <System>\redistributor.exe and
creates the file <System>\redist.dll.

The following registry entries are created to run code exported by redist.dll on
startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logons
DllName
<System>\redist.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logons
Impersonate
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer