Sophos

Troj/Hanlo-A

Aliases
  • Trojan-Downloader.Win32.Hanlo.a
  • Downloader-AFG
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from November 2005 (3.99)
Protection available since 22 September 2005 06:11:10 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Hanlo-A is a downloader Trojan which will download, install and run new
software without notification that it is doing so.

When Troj/Hanlo-A is installed the following file is created:

<System>\avupdate2.sys

The file avupdate2.sys is detected as Troj/Haxdor-Gen.

The file avupdate2.sys is registered as a new system driver service named "avupdate2", with a display name of "AVupdate service interface X2". Registry
entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\avupdate2\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer