Sophos

Troj/Sysbug-A

Aliases
  • Backdoor-CAG
Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from January 2004 (3.77)
Protection available since 25 November 2003 08:00:35 (GMT)
Detected by All Sophos products

Action

Please follow the instructions for removing Trojans.

Delete the files svc.sav and C:\temp35.txt in the Windows folder as mentioned above.

Windows NT/2000/XP/2003

In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SystemDebug

and delete it if it exists.

Close the registry editor.

More Information

Troj/Sysbug-A is a backdoor Trojan that steals system information and opens up a backdoor to allow unauthorised access to the compromised computer. This Trojan horse has been distributed in the form of an email with the following characteristics:

From: james2003@hotmail.com

Subject line: Re[2]: Mary

Message text:

Hello my dear Mary,

I have been thinking about you all night. I would like to apologize for the other night when we made beautiful love and did not use condoms. I know this was a mistake and I beg you to forgive me.

I miss you more than anything, please call me Mary, I need you. Do you remember when we were having wild sex in my house? I remember it all like it was only yesterday. You said that the pictures would not come out good, but you were very wrong, they are great. I didn't want to show you the pictures at first, but now I think it's time for you to see them. Please look in the attachment and you will see what I mean.

I love you with all my heart, James.

Attached file: Private.zip (contains wendynaked.jpg.exe)

Troj/Sysbug-A will copy itself to the Windows folder as sysdeb32.exe and adds the following registry entry to ensure it gets run at system logon:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SystemDebug

Troj/Sysbug-A creates the files svc.sav in the Windows folder and C:\temp35.txt. These files are not malicious and can simply be deleted.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer