Sophos

Troj/Small-EJG

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from August 2007 (4.20)
Protection available since 14 June 2007 09:42:09 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Small-EJG is a Trojan downloader for the Windows platform.

Troj/Small-EJG includes functionality to access the internet and communicate with a remote server via HTTP.

When Troj/Small-EJG is installed the following files are created:

<User>\Application Data\Microsoft\Network\Downloader\qmgr0.dat
<User>\Application Data\Microsoft\Network\Downloader\qmgr1.dat
<Root>\bit1.tmp

These file may be deleted.

The following registry entry is created to run code exported by {009541A0-3B00-1F1C-00F3-040224009C02} on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
WinCTL
{009541A0-3B00-1F1C-00F3-040224009C02}

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer