Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | April 2008 (4.28) |
| Protection available since | 8 February 2008 20:10:13 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Daymay-A is a Trojan for the Windows platform.
When first run Troj/Daymay-A copies itself to <Temp>\svchost.exe and creates the file <Current Folder>\Node00000000.ini.
The main purpose of Troj/Daymay-A is to participate as a node in a network of bots sending spam.
The following registry entries are set, affecting internet security:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
<pathname of the worm executable>
<Current Folder>\<original filename>:*:Enabled:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\IcmpSettings
AllowInboundEchoRequest
1
