Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Protection available since | 18 September 2004 16:26:30 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Small-KY will create the following registry entries in order to start automatically on user logon or computer restart:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
wpds.exe = <Windows System>\doriot.exe and
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
wpsds.exe = <Windows System>\doriot.exe
The injected DLL may attempt to download and execute components after saving them as _re_file.exe. Please note that the injected DLL is detected by Sophos Anti-Virus as Troj/Small-KV.
