Sophos

Troj/Tofdrop-B

Aliases
  • Trojan-Dropper.Win32.Small.ei
  • MultiDropper-OV
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 15 November 2005 08:03:53 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Tofdrop-B is a dropper Trojan for the Windows platform.

Troj/Tofdrop-B will drop and execute two files as scchost.exe and scchostc.exe to the Windows system folder. Both files are detected as Troj/Daemoni-H.

The following registry entry is created in order to run the dropped files:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Alive SYstem
<path to executables>

Sophos's anti-virus products include Genotype™ detection technology, which can proactively protect against new threats without requiring an update. Sophos customers have been protected against Troj/Tofdrop-B (detected as Troj/Tofdr-Fam) since version 3.98.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer