Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | November 2006 (4.11) |
| Protection available since | 8 September 2006 04:00:43 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Small-CPO is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.
The Trojan includes functionality to access the internet and communicate with a remote server via HTTP.
When run the Trojan copies itself to <System>\wininet.exe and creates the file <System>\svshost.dll. The file svshost.dll is detected as Troj/Small-CPO.
The following registry entry is set:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
SysRun
(D7FFD784-5276-42D1-887B-00267870A4C7)
The file svshost.dll is registered as a COM object, creating registry entries under:
HKCR\CLSID\(D7FFD784-5276-42D1-887B-00267870A4C7)
