Sophos

Troj/Dloadr-BSI

Aliases
  • Trojan.Win32.Obfuscated.abi
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from October 2008 (4.34)
Protection available since 5 September 2008 19:13:39 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dloadr-BSI includes functionality to access the internet and communicate with a remote server via HTTP.

When Troj/Dloadr-BSI is installed the following files are created:

<User>\Application Data\Microsoft\Crypto\rsa\S-1-5-21-854245398-413027322-725345543-1003\1c96f5e3071d2fe1fd8725ea7dbf2576_d94f23d0-c3c6-4280-a7c4-148368e4a6d9
<User>\Application Data\Microsoft\Protect\S-1-5-21-854245398-413027322-725345543-1003\6b93ae49-e30b-4770-957a-0caef1aeab5e
<User>\Application Data\Microsoft\Protect\S-1-5-21-854245398-413027322-725345543-1003\Preferred
<User>\Application Data\Microsoft\Protect\credhist
<System>\winqjn32.dll

The file winqjn32.dll is detected as Mal/Generic-A.

The following registry entries are created to run code exported by winqjn32.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winqjn32
DllName
winqjn32.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winqjn32
Impersonate
0

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winqjn32
Startup
EvtStartup

Registry entries are created under:

HKLM\SOFTWARE\Microsoft\MSSMGR

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer