Sophos

Troj/Small-DLH

Aliases
  • Trojan-Clicker.Win32.Small.kj
  • Generic
  • AdClicker.b
  • Win32/TrojanClicker.Small.KJ
  • TROJ_Generic
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2007 (4.17)
Protection available since 4 November 2006 00:36:10 (GMT)
Last updated 22 March 2007 22:08:03 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Small-DLH is a Trojan for the Windows platform.

Troj/Small-DLH includes functionality to access the internet and communicate with a remote server via HTTP.

When first run Troj/Small-DLH copies itself to <Windows>\svchost.exe and creates the following files:

<Temp>\Sys.htm
<Temp>\cc1.txt
<Windows>\syshost.dll

syshost.dll is also detected as Troj/Small-DLH and is used to hide files, processes and registry entries related to the Trojan. The other files are harmless and can be deleted safely.

The following registry entry is created to run Troj/Small-DLH on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
1
<Windows>\svchost.exe

Registry entries are created under:

HKLM\SOFTWARE\0D92R7F92J\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer