Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 7 April 2008 04:29:48 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Lydra-AD is a Trojan for the Windows platform.
When run Troj/Lydra-AD creates the files <System>\qmgr.dll (also detected as Troj/Lydra-AD) and <System>\user.dll (detected as Troj/DwnLdr-HCE).
Troj/Lydra-AD registers itself as a system service with the name "BITS" with a description of "Background Intelligent Transfer Service" and a startup type of automatic to run the malware on startup.
Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\BITS
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_BITS
