Sophos

Troj/Hanlo-B

Aliases
  • Trojan-Downloader.Win32.Hanlo.b
  • Downloader-AGH
  • TROJ_DLOADER.AJQ
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Included in our products from December 2005 (4.00)
Protection available since 24 October 2005 08:17:51 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Hanlo-B is a Trojan for the Windows platform.

Troj/Hanlo-B includes functionality to access the internet and communicate with a remote server via HTTP.

Troj/Hanlo-B downloads the following files:

tBmp107.exe
tBmp207.exe
tBmp307.exe
tBmp407.exe
tBmp507.exe
tBmp607.exe
tBmp707.exe Troj/Hanlo-B is a Trojan for the Windows platform.

Troj/Hanlo-B includes functionality to access the internet and communicate with a remote server via HTTP.

Troj/Hanlo-B downloads the following files:

tBmp107.exe
tBmp207.exe
tBmp307.exe
tBmp407.exe
tBmp507.exe
tBmp607.exe
tBmp707.exe

Troj/Hanlo-B creates the following file:

<System>\avA6.sys

The file avA6.sys is detected as Troj/Haxdor-Gen.

The file avA6.sys is registered as a new system driver service named "avA6", with a display name of "AVP update interface A6". Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\avA6\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer