Sophos

Troj/NewIfrm-A

Aliases
  • TrojanDownloader.Win32.Agent.dh
  • Downloader-QA
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2004 (3.87)
Protection available since 27 September 2004 08:38:54 (GMT)
Detected by All Sophos products

Action

More Information

Troj/NewIfrm-A is a Trojan downloader which will download commands from a predefined location on the internet. These commands include instructing Troj/NewIfrm-A to install more trojans, or to change Internet Explorer settings such as start page and search page.

Troj/NewIfrm-A will copies itself into %system32%\golumm\services.exe. It will also setup the following autostart registry entry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
sysinit = "%System32%\\golumm\\services.exe"

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
golumm = "%System32%\\golumm\\services.exe"

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer