Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | December 2005 (4.00) |
| Protection available since | 24 October 2005 08:17:51 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Hanlo-B is a Trojan for the Windows platform.
Troj/Hanlo-B includes functionality to access the internet and communicate with a remote server via HTTP.
Troj/Hanlo-B downloads the following files:
tBmp107.exe
tBmp207.exe
tBmp307.exe
tBmp407.exe
tBmp507.exe
tBmp607.exe
tBmp707.exe
Troj/Hanlo-B is a Trojan for the Windows platform.
Troj/Hanlo-B includes functionality to access the internet and communicate with a remote server via HTTP.
Troj/Hanlo-B downloads the following files:
tBmp107.exe
tBmp207.exe
tBmp307.exe
tBmp407.exe
tBmp507.exe
tBmp607.exe
tBmp707.exe
Troj/Hanlo-B creates the following file:
<System>\avA6.sys
The file avA6.sys is detected as Troj/Haxdor-Gen.
The file avA6.sys is registered as a new system driver service named "avA6", with a display name of "AVP update interface A6". Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\avA6\
