Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 6 April 2007 02:08:42 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/GrayBr-CP is a backdoor Trojan for the Windows platform.
When Troj/GrayBr-CP is installed the following files are created:
<user>\Local Settings\Temp\??????.bat
<user>\Local Settings\Temp\<variable>\???.exe
<user>\Local Settings\Temp\<variable>\z.exe
<Windows>\Hacker.com.cn.exe
<Windows>\Temp\z.exe
where ? is a digit 0-9 and <variable> is a temporary folder name.
The file Hacker.com.cn.exe (detected separately as Troj/GrayBr-Gen) is registered as a new file system driver service named "ALGE", with a display name of "ALGE" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\ALGE
