Sophos

Troj/Dumaru-S

Aliases
  • Backdoor.Win32.Dumador.az
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from February 2006 (4.02)
Protection available since 19 September 2005 13:20:12 (GMT)
Last updated 14 December 2005 23:39:55 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dumaru-S is a password stealing backdoor Trojan for the Windows platform.

When first run Troj/Dumaru-S copies itself to <System>\winldra.exe and creates the following files:

<Temp>\fe43e701.htm
<Windows>\dvpd.dll
<Windows>\netdx.dat

The following registry entry is created to run winldra.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
load32
<System>\winldra.exe

Troj/Dumaru-S can log keystrokes on an infected computer, steal email and ftp details, as well as information from Protected Storage.

Troj/Dumaru-S contains a backdoor component that downloads a text file that can instruct it to do any of the following:

Upload or download a file
Execute a file
Create a remote command prompt

Troj/Dumaru-S changes settings for Microsoft Internet Explorer by modifying values under:

HKCU\Software\Microsoft\Internet Explorer\Main\

Registry entries are created under:

HKCU\Software\SARS\

Troj/Dumaru-S also adds the following entries to an infected computer's Hosts file:

127.0.0.1 www.trendmicro.com
127.0.0.1 trendmicro.com
127.0.0.1 rads.mcafee.com
127.0.0.1 customer.symantec.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 updates.symantec.com
127.0.0.1 update.symantec.com
127.0.0.1 www.nai.com
127.0.0.1 nai.com
127.0.0.1 secure.nai.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 download.mcafee.com
127.0.0.1 www.my-etrust.com
127.0.0.1 my-etrust.com
127.0.0.1 mast.mcafee.com
127.0.0.1 ca.com
127.0.0.1 www.ca.com
127.0.0.1 networkassociates.com
127.0.0.1 www.networkassociates.com
127.0.0.1 avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 www.avp.com
127.0.0.1 kaspersky.com
127.0.0.1 www.f-secure.com
127.0.0.1 f-secure.com
127.0.0.1 viruslist.com
127.0.0.1 www.viruslist.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 mcafee.com
127.0.0.1 www.mcafee.com
127.0.0.1 sophos.com
127.0.0.1 www.sophos.com
127.0.0.1 symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 us.mcafee.com/root/
127.0.0.1 www.symantec.com

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer