This is a trojan detection. Unlike viruses, trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.
|
Minimum DAT
4509 (2005-06-08) Updated DAT4509 (2005-06-08) |
Minimum Engine
5.1.00 File Length164,356 bytes |
Description Added
2005-06-08 Description Modified2005-09-28 |
When executed it copies itself to the %Windir% folder as:
It further drops a DLL component under the name firewall_anti.dll into the %Windir% folder. This DLL is injected into the same memory space as Explorer.exe.
The following registry keys is created so that it runs each time after a reboot:
The following registry key is created so that it runs as a service:
It blocks access to any of the following websites:
Trojans do not self-replicate. They are spread manually, often under the premise that the executable is something beneficial. Distribution channels include IRC, peer-to-peer networks, newsgroup postings, etc. .
Detection is included in our BETA DAT files and will also be included in the next scheduled DAT release. In addition to the DAT version requirements for detection, the specified engine version (or greater) must also be used.