Sophos

Troj/DwnLdr-FXH

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2007 (4.17)
Protection available since 7 December 2006 04:19:36 (GMT)
Last updated 15 March 2007 07:56:03 (GMT)
Detected by All Sophos products

Action

More Information

Troj/DwnLdr-FXH is a downloader Trojan for the Windows platform.

When run Troj/DwnLdr-FXH copies itself to <System>\wdfmgr32.exe and sets the following registry entry to run itself on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
wdfmgr32
<System>\wdfmgr32.exe

Troj/DwnLdr-FXH includes functionality to inject code into system processes.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer