Sophos

Troj/Cdopen-E

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from January 2006 (4.01)
Protection available since 10 November 2005 15:17:22 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Cdopen-E is a Trojan for the Windows platform.

Troj/Cdopen-E plays music and repeatedly opens and closes the CD tray.

The Trojan creates the following registry entry in an attempt to run itself on startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Photoshop
<Program Files>\svchost.exe

The following registry entries are set, disabling system restore:

HKCU\Software\Policies\Microsoft\Windows NT\SystemRestore
DisableConfig
1

HKCU\Software\Policies\Microsoft\Windows NT\SystemRestore
DisableSR
1

HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore
DisableConfig
1

HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore
DisableSR
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer