Summary

Summary
Action
More Information
| Detected by | All Sophos products |
|---|---|
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
Please read the instructions for removing Trojans.
More Information
Troj/CyberS-13B is a backdoor Trojan. When the Trojan server is running on a computer, that computer is vulnerable to unauthorised access attacks from network locations. In order to gain access to the infected computer an attacker has to run the Trojan client program.
The server program is copied to the file C:\Windows\System\~cab001.exe.
The value "Regcheck" is added to the following registry keys and points to the copy of the server:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
This will start the server when the victim's machine is rebooted. An entry is also added to the file win.ini that will attempt to start the server when Windows starts up.
