Sophos

Troj/Cimuz-CD

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2007 (4.18)
Protection available since 11 April 2007 19:40:44 (GMT)
Last updated 27 April 2007 13:13:15 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Cimuz-CD is a backdoor Trojan for the Windows platform.

Troj/Cimuz-CD includes functionality to access the internet and communicate with a remote server.

Troj/Cimuz-CD attempts to turn off anti-virus applications.

When first run Troj/Cimuz-CD copies itself to <System>\mstsdsc.exe and creates the following registry entry in order to run on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
mstsdsc.exe
<System>\mstsdsc.exe

Troj/Cimuz-CD creates the following files:
<System>\sporder.dll
<System>\tmwsock.dll

The file sporder.dll is a Windows networking library and is not inherently malicious. The file tmwsock.dll is also detected as Troj/Cimuz-CD.

The following registry entry is set to allow Troj/Cimuz-CD to bypass the Windows firewall:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
<System>\mstsdsc.exe
<System>\mstsdsc.exe:*:Enabled:mstsdsc

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer