Sophos

Troj/Slsorve-B

Aliases
  • Trojan-Downloader.Win32.VB.lq
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from September 2005 (3.97)
Protection available since 12 July 2005 12:48:51 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Slsorve-B is a Trojan for the Windows platform.

Troj/Slsorve-B includes functionality to download, install and run new software.

When first run Troj/Slsorve-B copies itself to <System>\lsas32.exe.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
678
<System>\lsas32.exe

Troj/Slsorve-B attempts to terminate the following security related processes:

assistse.exe
ravmon.exe
ravtimer.exe
rfw.exe
kavpfw.exe
kpfwsvc.exe
kavstart.exe
kwatch.exe
kavplus.exe
mailmon.exe
kpopmon.exe
kwatchui.exe
kavsvc.exe
kvapfw.exe
kvfw.exe
kvmonxp.kxp
kvsrvxp.exe
kvxp.kxp
kvcenter.kxp
defwatch.exe
rtvscan.exe
ccapp.exe
ccsetmgr.exe
vptray.exe
passwordguard.exe
eghost.exe
iparmor.exe
pfw.exe
teregpct.exe
dfvsnet.exe
netbargp.exe
nmain.exe
navw32.exe
kavsvcui.exe
kav32.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer