Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | November 2008 (4.35) |
| Protection available since | 6 October 2008 23:22:14 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Dloadr-BUP is a downloader Trojan for the Windows platform.
When first run Troj/Dloadr-BUP copies itself to <Windows>\updater.com with the hidden, system and read-only attributes set and creates the following registry entries to run updater.com on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
Windows Updater
updater.com
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Windows Updater
updater.com
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Windows Updater
updater.com
The following registry entries are set, disabling system software:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
DisableRegistrytools
1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
DisableTaskMgr
1
