Sophos

Troj/Hearse-A

Aliases
  • TROJ_HEARSE.A
  • Trojan.Goldun.K
  • Trojan-Spy.Win32.Goldun.im
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from May 2006 (4.05)
Protection available since 27 March 2006 21:09:55 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Hearse-A is a Trojan for the Windows platform.

The Trojan creates two files detected as members of the Haxdoor family of password stealing Trojans. Troj/Hearse-A is a Trojan for the Windows platform.

When run the Trojan creates the following files:

<Windows system folder>\zopenssl.dll
<Windows system folder>\zopenssld.sys

The file zopenssl.dll is detected as Troj/Haxdor-Fam and the file zopenssld.sys is detected as Troj/Haxdor-Gen.

The following registry entries are created in order to load the zopenssl.dll file each time a user logs on:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\zopenssl
Asynchronous
dword:00000001

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\zopenssl
DllName
zopenssl.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\zopenssl
Impersonate
dword:00000001

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\zopenssl
MaxWait
dword:00000001

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\zopenssl
nk48id
"[88BF38A86A50D1EAA]"

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\zopenssl
Startup
"zopenssl"

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer