Sophos

Troj/LowZone-CX

Aliases
  • Trojan.Win32.LowZones.dt
  • QLowZones-2.gen
  • Trojan.LowZones
  • TROJ_LOWZONE.AF
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2007 (4.17)
Protection available since 7 July 2006 22:09:27 (GMT)
Last updated 25 March 2007 02:34:35 (GMT)
Detected by All Sophos products

Action

More Information

Troj/LowZone-CX is a Trojan for the Windows platform.

Troj/LowZone-CX includes functionality to access the internet and communicate with a remote server via HTTP. Troj/LowZone-CX is a Trojan for the Windows platform.

Troj/LowZone-CX includes functionality to access the internet and communicate with a remote server via HTTP.

When first run Troj/LowZone-CX copies itself to <Windows system folder>\bikini.exe.

The following registry entry is created to run bikini.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
bikini
bikini.exe

The following registry entry is set, affecting internet security:

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
CurrentLevel
11

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer