Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Included in our products from | January 2006 (4.01) |
| Protection available since | 11 November 2005 14:51:04 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Elburro-A is a backdoor Trojan for the Windows platform.
Troj/Elburro-A can retrieve email addresses stored on an infected computer, send emails as specified by a remote intruder, get details about an infected system, download and execute files, and modify registry entries.
When first run, Troj/Elburro-A creates the following folders:
<Windows>\msapps
<Windows>\msapps\msinfo
<Windows>\msapps\msinfo\dat
Troj/Elburro-A creates the following registry entry:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
msappts32
<Windows>\msapps\msinfo\msappts32.exe
Troj/Elburro-A will also attempt to close any windows open with the following text in the title:
ubphost
Barra UOL
sys
Editor do Registro
Gerenciador de tarefas do Windows
Utilitario de configuracao do sistema
Firewall do Windows
Central de Seguranha do Windows
WINDOWS
msinfo
dat
msapps
On computers with the Windows firewall installed, Troj/Elburro-A will attempt to add itself as an authorized application.
