Alert ID : FrSIRT/ALRT-2008-02839
Aliases : N/A
Size : N/A
Rated as : Low Risk Release Date : 2008-05-13
Description
Troj/Dloadr-BLP when run downloads further malware to the folder <Documents and Settings>\All Users\_qbothome. Troj/Dloadr-BLP also creates the following registry entry so that the downloaded files autorun at startup: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run nwiz "C:\documents and settings\all users\_qbothome\_qbotinj.exe" "C:\documents and settings\all users\_qbothome\_qbot.dll" /c nwiz.exe /installquiet .