Sophos

Troj/Small-CPO

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2006 (4.11)
Protection available since 8 September 2006 04:00:43 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Small-CPO is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.

The Trojan includes functionality to access the internet and communicate with a remote server via HTTP.

When run the Trojan copies itself to <System>\wininet.exe and creates the file <System>\svshost.dll. The file svshost.dll is detected as Troj/Small-CPO.

The following registry entry is set:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
SysRun
(D7FFD784-5276-42D1-887B-00267870A4C7)

The file svshost.dll is registered as a COM object, creating registry entries under:

HKCR\CLSID\(D7FFD784-5276-42D1-887B-00267870A4C7)

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer