Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | July 2005 (3.95) |
| Protection available since | 17 May 2005 19:31:50 (GMT) |
| Last updated | 18 May 2005 14:28:47 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/CmjSpy-U is a keyboard-logging Trojan for the Windows platform.
When the Trojan is installed it copies itself to <Windows system folder>\msdrv.exe.
The following registry entry is created to run msdrv.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe "<Windows system folder>\msdrv.exe"
The Trojan creates a library file (also detected as Troj/CmjSpy-U) in the Temporary folder and injects code into the explorer process to load this library file.
The Trojan submits logged information to a preconfigured website using HTTP GET.
