Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | July 2008 (4.31) |
| Protection available since | 13 May 2008 23:20:14 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Iyus-V is a Trojan for the Windows platform.
Troj/Iyus-V includes functionality to access the internet and communicate with a remote server via HTTP.
When first run Troj/Iyus-V copies itself to <System>\mshelp.exe and creates the file <System>\sqla.dll. The file sqla.dll is not malicious and may be deleted.
The following registry entries are created to run mshelp.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Generic Host Process for WinXP Services
mshelp.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Generic Host Process for WinXP Services
mshelp.exe
Registry entries are set as follows:
HKCU\Software\Microsoft\Internet Explorer\International\CpMRU
Enable
1
HKCU\Software\Microsoft\Internet Explorer\International\CpMRU
Size
a
HKCU\Software\Microsoft\Internet Explorer\International\CpMRU
InitHits
64
HKCU\Software\Microsoft\Internet Explorer\International\CpMRU
Factor
14
