Sophos

Troj/DwnLdr-HLM

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from February 2009 (4.38)
Protection available since 4 December 2008 09:20:22 (GMT)
Detected by All Sophos products

Action

More Information

Troj/DwnLdr-HLM is a Trojan for the Windows platform.

When run Troj/DwnLdr-HLM creates the files:
<System>\jdk-1_5_0_19-windows-i393-pp\jav.bat - can be removed
<System>\jdk-1_5_0_19-windows-i393-pp\de.class - detected as Troj/DwnLdr-HLM
<System>\jdk-1_5_0_19-windows-i393-pp\js.exe - detected as Troj/DwnLdr-HLL

Troj/DwnLdr-HLM sets the following registry entries:

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
Java VM v6.9.2
(blank)

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Java VM v6.9.2
<System>\jdk-1_5_0_19-windows-i393-pp\jav.bat

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Java VM v6.9.2
(blank)

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Java VM v6.9.2
<System>\jdk-1_5_0_19-windows-i393-pp\jav.bat

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer