Sophos

Troj/Dloadr-BCP

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Email attachments
  • Web browsing
Affected operating systems Windows
Characteristics
  • Drops more malware
Included in our products from September 2007 (4.21)
Protection available since 2 August 2007 13:51:42 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dloadr-BCP is a Trojan for the Windows platform.

Troj/Dloadr-BCP has been spammed out in email messages masquerading as free photos/videos of celebrities.

When Troj/Dloadr-BCP is run it creates the file <System>\drivers\runtime.sys. This file is already detected as Troj/NTRootK-BY. The file runtime.sys is registered as a new system driver service named "runtime". Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\runtime

Troj/Dloadr-BCP also drops the file <System>\drivers\secdrv.sys (overwriting existing file if it exists). This file is already detected as Troj/Agent-FVT.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer