Sophos

Troj/Daymay-A

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Web browsing
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from April 2008 (4.28)
Protection available since 8 February 2008 20:10:13 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Daymay-A is a Trojan for the Windows platform.

When first run Troj/Daymay-A copies itself to <Temp>\svchost.exe and creates the file <Current Folder>\Node00000000.ini.

The main purpose of Troj/Daymay-A is to participate as a node in a network of bots sending spam.

The following registry entries are set, affecting internet security:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
<pathname of the worm executable>
<Current Folder>\<original filename>:*:Enabled:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\IcmpSettings
AllowInboundEchoRequest
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer