Need help? Ask the community or hire an expert.
Go to Avira Answers
Virus:BDS/Androm.EB.117
Date discovered:16/05/2013
Type:Trojan
In the wild:Yes
Reported Infections:Medium to high
Distribution Potential:Medium
Damage Potential:Low to medium
Static file:Yes
File size:84.992 Bytes
MD5 checksum:5C9341C4C2A72FE4B6A3333E0FEA10B8
VDF version:7.11.78.244 - Thursday, May 16, 2013
IVDF version:7.11.78.244 - Thursday, May 16, 2013

 General Method of propagation:
   • Email


Aliases:
   •  Kaspersky: Trojan-Dropper.Win32.Dorifel.adpt
   •  Sophos: Troj/Agent-ABTI
   •  Eset: Win32/TrojanDownloader.Wauchos.I
   •  DrWeb: Trojan.Inject2.23
   •  Fortinet: W32/Dorifel.ADPT!tr
   •  Rising: Trojan.Agent!534F


Platforms / OS:
   • Windows 2000
   • Windows XP
   • Windows 2003
   • Windows Vista
   • Windows Server 2008
   • Windows 7


Side effects:
   • Drops a malicious file
   • Registry modification

 Files It copies itself to the following location:
   • %ALLUSERSPROFILE%\svchost.exe

 Registry The following registry key is added in order to run the process after reboot:

– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   • "SunJavaUpdateSched"="%ALLUSERSPROFILE%\svchost.exe"

Description inserted by Eric Burk on Friday, May 17, 2013
Description updated by Eric Burk on Friday, May 17, 2013

Back . . . .