Sophos

Troj/Dloadr-BUP

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2008 (4.35)
Protection available since 6 October 2008 23:22:14 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dloadr-BUP is a downloader Trojan for the Windows platform.

When first run Troj/Dloadr-BUP copies itself to <Windows>\updater.com with the hidden, system and read-only attributes set and creates the following registry entries to run updater.com on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
Windows Updater
updater.com

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Windows Updater
updater.com

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Windows Updater
updater.com

The following registry entries are set, disabling system software:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
DisableRegistrytools
1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
DisableTaskMgr
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer