Sophos

Troj/Dluca-I

Aliases
  • Downloader-DC
  • trojan
Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from August 2004 (3.84)
Protection available since 28 June 2004 10:00:29 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dluca-I is a downloader Trojan which downloads executables from remote
servers and installs/runs them.

When first run Troj/Dluca-I copies itself to the Windows system folder as
sncntr.exe and creates the following registry entry, so that sncntr.exe is run
automatically on startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
sncntr = %SYSTEM%\sncntr.exe /nocomm

Registry entries are also created under:

HKCU\Software\sncntr\
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sncntr\

Troj/Dluca-I can be uninstalled via the Add or Remove Programs dialog in the
Windows Control Panel (Start - Settings - Control Panel - Add/Remove
Programs by selecting "sncntr" from the list.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer