Sophos

Troj/Psupda-A

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Included in our products from October 2005 (3.98)
Protection available since 11 August 2005 05:03:50 (GMT)
Last updated 17 August 2005 18:11:39 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Psupda-A is a downloader Trojan which will download, install and run new software without notification that it is doing so.

Troj/Psupda-A includes functionality to inject its code into SVCHOST.EXE.

When Troj/Psupda-A is installed the following files are created and run:

<System>\Ywvpysxl.d1l
<System>\drivers\Ywvpysxl.sys

The file Ywvpysxl.d1l is detected as Troj/Psupda-A.

The file Ywvpysxl.sys is detected as Troj/RKProc-B.

The file Ywvpysxl.sys is registered as a new hidden system driver service named "Ywvpysxl" with a display name of "Ywvpysxl" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\Ywvpysxl\

Troj/Psupda-A then uses the system driver service to stealth itself.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer