Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 16 October 2004 15:51:01 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/TubbyT-A is a multi-component Trojan which attempts to download and execute an EXE from a remote URL without the user's knowledge.
The dropper component of the Trojan drops and registers a DLL called adv.dll within the Windows system folder and then deletes itself.
The DLL component creates the following registry entry to run itself on system restart:
HKLM\SOFTWARE\Classes\CLSID\{9EAC0102-5E61-2312-BC2D-414456544F4E}\
InprocServer32\@ = <Windows system>\adv.dll
Troj/TubbyT-A may also change the default Microsoft Internet Explorer start page by modifying the following registry entry:
HKLM\Software\Microsoft\Internet Explorer\Main
The DLL component which contains the download capability can be unregistered by executing the following command:
regsvr32 /u <Windows system>\adv.dll
