Sophos

Troj/Stinx-R

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from March 2006 (4.03)
Protection available since 30 January 2006 20:08:13 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Stinx-R is a backdoor Trojan for the Windows platform.

The Trojan connects to an IRC server and joins a predetermined channel. The Trojan then accepts commands from remote attackers. Troj/Stinx-R is a backdoor Trojan for the Windows platform.

When first run Troj/Stinx-R copies itself to <System>\csrnvrt.exe and creates two randomly named BAT files in the Temp folder. One of these files is used to attempt to bypass the Windows firewall. The other is used to delete the original copy of the Trojan.

The following registry entries are created to run csrnvrt.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
DriverModule
csrnvrt.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
DriverModule
csrnvrt.exe

The Trojan connects to an IRC server and joins a predetermined channel. The Trojan then accepts commands from remote attackers.

The Trojan may also download further malicious code.

Troj/Stinx-R attempts to terminate a number of processes, including some belonging to anti-virus applications.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer