Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | February 2007 (4.14) |
| Protection available since | 21 November 2006 16:57:38 (GMT) |
| Last updated | 12 December 2006 13:41:57 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Lager-S is an email-relaying Trojan for the Windows platform.
Troj/Lager-S can be used to send spam. The content of the messages it sends is downloaded from a preconfigured website.
When first run Troj/Lager-S copies itself to <System>\taskdir.exe and creates the following files:
<System>\adir.dll
<System>\zlbw.dll
The file adir.dll is detected as Troj/HideDl-B.
The file zlbw.dll is not malicious and can be safely deleted.
The following registry entry is created to run taskdir.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
taskdir
<System>\taskdir.exe
