Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 26 April 2006 20:13:36 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Small-BNO is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.
Troj/Small-BNO includes functionality to access the internet and communicate with a remote server via HTTP.
When Troj/Small-BNO is installed it creates the file <User>\Documents\Settings\polymorph.dll.
The following registry entries are created to run code exported by polymorph.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\polymorphreg
DllName
<User>\Documents\Settings\polymorph.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\polymorphreg
Startup
polymorphreg
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\polymorphreg
Impersonate
1
