Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | March 2007 (4.15) |
| Protection available since | 1 February 2007 10:12:04 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/DwnLdr-FZZ is a downloader Trojan for the Windows platform.
When run Troj/DwnLdr-FZZ creates the following files:
<Windows>\asver.ger
<Windows>\ftp.txt
The files asver.ger and ftp.txt are not malicious and can be safely deleted.
Troj/DwnLdr-FZZ includes functionality to:
- modify the HOSTS file
- download code via FTP
Troj/DwnLdr-FZZ also creates the following files:
<Windows>\initial.bat - detected as Troj/DwnLdr-FZZ
<Windows>\svc.bat - detected as Troj/DwnLdr-FZZ
<System>\win32.bat - detected as Troj/DwnLdr-FZZ
The following registry entry is set to run Troj/DwnLdr-FZZ on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
PC2X
<Windows>\initial.bat
