Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | March 2008 (4.27) |
| Protection available since | 23 January 2008 19:04:16 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Dropper-TG is a Trojan for the Windows platform.
When Troj/Dropper-TG is installed the following files are created:
<Favorites>\<non-ASCII characters>.url
<System>\drivers\h2pnhd.sys
<System>\drivers\ojf6n62n.sys
<System>\kt2py.dll
The file kt2py.dll is detected as Mal/Behav-010 and the file h2pnhd.sys is detected as Troj/RootCK-Gen.
The file h2pnhd.sys is registered as a new system driver service named "h2pnhd", with a display name of "h2pnhd" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\h2pnhd
The file ojf6n62n.sys is registered as a new system driver service named "ojf6n62n", with a display name of "ojf6n62n" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\ojf6n62n
Registry entries are created under:
HKLM\SOFTWARE\Microsoft\IE4
