Sophos

Troj/Elburro-A

Aliases
  • Trojan-Downloader.Win32.Dadobra.jg
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from January 2006 (4.01)
Protection available since 11 November 2005 14:51:04 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Elburro-A is a backdoor Trojan for the Windows platform.

Troj/Elburro-A can retrieve email addresses stored on an infected computer, send emails as specified by a remote intruder, get details about an infected system, download and execute files, and modify registry entries.

When first run, Troj/Elburro-A creates the following folders:

<Windows>\msapps
<Windows>\msapps\msinfo
<Windows>\msapps\msinfo\dat

Troj/Elburro-A creates the following registry entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
msappts32
<Windows>\msapps\msinfo\msappts32.exe

Troj/Elburro-A will also attempt to close any windows open with the following text in the title:

ubphost
Barra UOL
sys
Editor do Registro
Gerenciador de tarefas do Windows
Utilitario de configuracao do sistema
Firewall do Windows
Central de Seguranha do Windows
WINDOWS
msinfo
dat
msapps

On computers with the Windows firewall installed, Troj/Elburro-A will attempt to add itself as an authorized application.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer