Home > Support > Global Security Advisor 

Virus Detail

Win32/Spudrag

Date Published:
1 Aug 2005

Last Updated:
23 Jan 2006

Threat Assessment

Overall Risk:   Very Low
Wild:  Low
Destructiveness:  Low
Pervasiveness:  None

Characteristics

Type : Trojan

Category : Win32

Also known as:   DesktopHijack (McAfee), Trojan.Desktophijack.B (Symantec), Druogna (McAfee), Win32/Druogna.7168!Trojan, W32/FakeAlert.Z (F-Secure), Win32/Spudrag!generic, Win32/Spudrag.6144!Trojan, Win32.Spudrag.A, Win32.Spudrag.B, Win32.Spudrag.C, Troj/Spyjack-A (Sophos), Troj/Spyjack-C (Sophos), Trojan.Win32.Agent.ff (Kaspersky), Trojan.Win32.Small.eu (Kaspersky), Trojan.Win32.Small.ev (Kaspersky)

Immediate Protection Info

 
 
 
 

Description

Win32/Spudrag is a family of trojans dropped by several Win32.Alemod variants to display a fake infected message. This message is intended to intimidate users into downloading a dubious 'spyware' scanning application.

Back to top

Method of Infection

Several Alemod variants drop and execute a file %System%\intel32.exe, or  %System%\intell32.exe  which displays a red alert icon in the system tray. This file may be detected as Win32.Spudrag by CA antivirus solutions. If the user hovers their mouse over the icon, it displays the following message:


"Your computer is infected!"

If the user right-clicks on the icon, it displays this message:


"Click here to protect your computer from spyware / virus threat."

Fake infected message displayed by Win32.Spudrag


Should the user left-click on the icon, the trojan launches the user's default Internet browser to display a particular webpage.


Alemod also modifies the registry so that this file is executed at each Windows start:


HKLM\Software\Microsoft\Windows\CurrentVersion\Run\intel32.exe = "%System%\intel32.exe"


or


HKLM\Software\Microsoft\Windows\CurrentVersion\Run\intell32.exe = "%System%\intell32.exe"


For more information on Win32.Alemod variants that drop Win32.Spudrag, please see elsewhere in our encyclopedia:


Note: '%System%' is a variable location. The malware determines the location of the current System folder by querying the operating system. The default installation location for the System directory for Windows 2000 and NT is C:\Winnt\System32; for 95,98 and ME is C:\Windows\System; and for XP is C:\Windows\System32.


Back to top

CA Global Security Advisor

Current threat condition: Low
Low
Find Threats
Viruses Spyware
Vulnerabilities All

Security Resources

 
 
Page Tools