Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 1 November 2005 15:28:44 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Small-ER is a backdoor Trojan which can be used as a proxy and
is capable of downloading and executing arbitrary files.
Troj/Small-ER drops child.dll in the Windows system folder and sets the
following registry entries to ensure startup on system logon.
HKCR\CLASSES\CLSID\(4F141CBA-1457-6CCA-03A7-7AA21B61EA0F)
InProcServer32
<System>\child.dll
HKCR\CLSID\(4F141CBA-1457-6CCA-03A7-7AA21B61EA0F)
InProcServer32\ThreadingModel
Apartment
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ SharedTaskScheduler\
(4F141CBA-1457-6CCA-03A7-7AA21B61EA0F)
OutPost FireWall
To avoid detection, Troj/Small-ER may delete netlog.exe on startup.
