Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | June 2007 (4.18) |
| Protection available since | 11 April 2007 19:40:44 (GMT) |
| Last updated | 27 April 2007 13:13:15 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Cimuz-CD is a backdoor Trojan for the Windows platform.
Troj/Cimuz-CD includes functionality to access the internet and communicate with a remote server.
Troj/Cimuz-CD attempts to turn off anti-virus applications.
When first run Troj/Cimuz-CD copies itself to <System>\mstsdsc.exe and creates the following registry entry in order to run on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
mstsdsc.exe
<System>\mstsdsc.exe
Troj/Cimuz-CD creates the following files:
<System>\sporder.dll
<System>\tmwsock.dll
The file sporder.dll is a Windows networking library and is not inherently malicious. The file tmwsock.dll is also detected as Troj/Cimuz-CD.
The following registry entry is set to allow Troj/Cimuz-CD to bypass the Windows firewall:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
<System>\mstsdsc.exe
<System>\mstsdsc.exe:*:Enabled:mstsdsc
