Sophos

Troj/Puper-T

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from February 2006 (4.02)
Protection available since 9 December 2005 15:34:29 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Puper-T is a browser hijacking Trojan for the Windows platform.

When Troj/Puper-T is installed the following files are created:

<System>\hpXXX.tmp - where XXX denotes randomly generated characters.
<System>\msvol.tlb
<System>\ncompat.tlb

The file hpXXX.tmp is registered as a COM object and Browser Helper Object (BHO)
for Microsoft Internet Explorer, creating registry entries under:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects\(724510c3-f3c8-4fb7-879a-d99f29008a2f)
HKCR\CLSID\(724510C3-F3C8-4FB7-879A-D99F29008A2F)

Troj/Puper-T changes search settings for Microsoft Internet Explorer by
modifying values under:

HKCU\Software\Microsoft\Internet Explorer\Search\

Registry entries are set as follows:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objecta\(724510c3-f3c8-4fb7-879a-d99f29008a2f)\

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objecta\(724510c3-f3c8-4fb7-879a-d99f29008a2f)\(default)

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run
nvctrl.exe
nvctrl.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer