Sophos

Troj/Dwnldr-HIT

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2008 (4.35)
Protection available since 7 October 2008 20:03:16 (GMT)
Detected by All Sophos products

Action

More Information

When first run, Troj/Dwnldr-HIT copies itself to the following location:

<Windows>\services.exe

Troj/Dwnldr-HIT attempts to download and run code from the internet.

Troj/Dwnldr-HIT also attempts to disable the Windows firewall with the following registry entries:

HKLM\SOFTWARE\Microsoft\Security Center
FirewallDisableNotify
0x00000001

HKLM\SOFTWARE\Microsoft\Security Center
FirewallOverride
0x00000001

HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile
EnableFirewall
0x00000000

HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile
EnableFirewall
0x00000000

Troj/Dwnldr-HIT tries to ensure that it is started when Windows starts via the following registry entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\services
<Windows>\services.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer