Sophos

Troj/Dowdec-A

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Included in our products from December 2006 (4.12)
Protection available since 29 August 2006 09:43:11 (GMT)
Last updated 25 October 2006 08:08:25 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dowdec-A is a downloader Trojan for the Windows platform.

When Troj/Dowdec-A is installed the following files are created:

<Temp>\check.bmp - this file may be deleted
<Temp>\gfdr.bat - this file may be deleted
<System>\msvoid.dll - detected as Troj/Dowdec-Gen.

The file msvoid.dll is registered as a COM object and Browser Helper Object
(BHO) for Microsoft Internet Explorer, creating registry entries under:

HKCR\CLSID\(CE453468-C4F4-A3DE-7FBD-4569594A7FE9)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects\(CE453468-C4F4-A3DE-7FBD-4569594A7FE9)

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer