Sophos

Troj/Dropper-QL

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from August 2007 (4.20)
Protection available since 10 July 2007 07:20:06 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dropper-QL is a Trojan for the Windows platform.

Troj/Dropper-QL includes functionality to access the internet and communicate with a remote server via HTTP.

When Troj/Dropper-QL is installed the following files are created:

<System>\rsvp32_2.dll- detected as Troj/SpamToo-AR.
<System>\sporder.dll - Clean File
<Windows>\zupacha.exe - detected as Troj/SpamToo-AR.

The following registry entry is created to run zupacha.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\<Root>\WINDOWS
zupacha.exe
<Windows>\zupacha.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer