Sophos

Troj/Loony-O

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2004 (3.87)
Protection available since 4 October 2004 13:20:39 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Loony-O is an IRC backdoor Trojan which allows unauthorised access and control of the computer from a remote network location.

In order to run automatically when Windows starts up the Trojan copies itself to the file winsys32.exe in the Windows system folder and creates the following registry entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\winsys32 Driver

Sophos Anti-Virus version 3.85 detects this Trojan as Troj/Loony-Gen without requiring an update.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer