Sophos

Troj/Puper-E

Aliases
  • Trojan.Win32.Puper.e
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from June 2005 (3.94)
Protection available since 6 May 2005 08:43:13 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Puper-E is a Trojan for Windows based systems.

The Trojan drops a file named intmonp.exe into the Windows system folder and then runs it. The intmonp.exe file monitors the Trojan and restarts it if it is terminated. The Trojan restarts the monitoring process if it is terminated and recreates it if deleted.

Troj/Puper-E also creates the following registry entry to ensure it is run when the infected computer starts:

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
notepad2.exe
popuper.exe

Troj/Puper-E also monitors this registry entry and will restore it if it is changed or deleted.

Troj/Puper-E may monitor internet sessions and log visited URLs.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer