Sophos

Troj/Nordex-A

Aliases
  • Trojan.Win32.Agent.aau
  • Trojan-Dropper.Win32.Small.atq
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from June 2007 (4.18)
Protection available since 9 November 2006 11:31:51 (GMT)
Last updated 14 April 2007 01:16:18 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Nordex-A is a downloading Trojan for the Windows platform.

Troj/Nordex-A includes functionality to access the internet and communicate with a remote server via HTTP. Troj/Nordex-A is a downloading Trojan for the Windows platform.

Troj/Nordex-A includes functionality to access the internet and communicate with a remote server via HTTP.

The Trojan may arrive disguising itself as a genuine MS update in an archive dropper that contains a Trojan downloading component.

When Troj/Nordex-A is installed the following files are created:

<User>\Local Settings\Temp\<random>.tmp.exe
<User>\Local Settings\Temp\<random>.tmp.dll
<User>\Local Settings\Temp\WER1.tmp.dir00/appcompat.txt
<Windows>\kb823980.log
<System>\xpsp1hfm.exe
<Windows>\xpsp1hfm.log

where the <random>.tmp.dll file is also detected as Troj/Nordex-A. The rest of the files are not malicious and may be safely deleted.

Registry entries are set under :

HKCU\Software\Microsoft\Notepad

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer