Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | October 2008 (4.34) |
| Protection available since | 5 September 2008 19:13:39 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Dloadr-BSI includes functionality to access the internet and communicate with a remote server via HTTP.
When Troj/Dloadr-BSI is installed the following files are created:
<User>\Application Data\Microsoft\Crypto\rsa\S-1-5-21-854245398-413027322-725345543-1003\1c96f5e3071d2fe1fd8725ea7dbf2576_d94f23d0-c3c6-4280-a7c4-148368e4a6d9
<User>\Application Data\Microsoft\Protect\S-1-5-21-854245398-413027322-725345543-1003\6b93ae49-e30b-4770-957a-0caef1aeab5e
<User>\Application Data\Microsoft\Protect\S-1-5-21-854245398-413027322-725345543-1003\Preferred
<User>\Application Data\Microsoft\Protect\credhist
<System>\winqjn32.dll
The file winqjn32.dll is detected as Mal/Generic-A.
The following registry entries are created to run code exported by winqjn32.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winqjn32
DllName
winqjn32.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winqjn32
Impersonate
0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winqjn32
Startup
EvtStartup
Registry entries are created under:
HKLM\SOFTWARE\Microsoft\MSSMGR
