Sophos

Troj/Dowdec-Gen

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from July 2007 (4.19)
Protection available since 25 August 2006 14:21:44 (GMT)
Last updated 19 May 2007 07:00:08 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dowdec-Gen is a family of Trojan downloaders for the Windows platform.

Members of Troj/Dowdec-Gen usually consist of an executable file that drops a dll to the Windows system folder. The executable will sometimes drop a batch file to the Temp folder in order to delete itself, and may also drop a clean text or image file to the Temp folder.

The dropped dll is registered as a COM object and Browser Helper Object (BHO) for Microsoft Internet Explorer, creating registry entries under:

HKCR\CLSID\(clsid)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\(clsid)

Some members of Troj/Dowdec-Gen have been seen in the form of a ZIP file attached to spam email.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer