Home Malware Programs Trojans Trojan-Downloader.Dadobra!sd5

Trojan-Downloader.Dadobra!sd5

Posted: June 15, 2010

Trojan-Downloader.Dadobra!sd5 is a variant of a Trojan downloader that typically installs itself onto a PC via security exploits. Once active, Trojan-Downloader.Dadobra!sd5 facilitates downloading additional malware onto the system. Remove Trojan-Downloader.Dadobra!sd5 immediately using a reliable malware remover.

Aliases

IRC-Worm.Win32.Fagot.a (Kaspersky Lab)
W32/Petch.worm!irc (McAfee)
W32/Fagot-A (Sophos)
Worm:Win32/Fagot.A (Microsoft)
Win32/Fagot.worm.381952 (AhnLab)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\chcp.exe
    2 %System%\dllhost32.exe
    3 %System%\logon.exe
    4 %System%\userinit32.exe
    5 %System%\win.exe
    6 %System%\wuauclt.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Loading...