Sophos

Troj/Tibs-PI

Aliases
  • Trojan-Proxy.Win32.Lager.eg
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from January 2007 (4.13)
Protection available since 16 November 2006 09:50:43 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Tibs-PI is an email relaying Trojan for the Windows platform.

The Trojan can be used to send spam. The content of the messages it sends is downloaded from a preconfigured website.

When first run the Trojan copies itself to <System>\taskdir.exe and creates the
following files:

<System>\adir.dll (Detected by Sophos as Troj/HideDl-B)

The following registry entry is created to run taskdir.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
taskdir
<System>\taskdir.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer