Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | August 2005 (3.96) |
| Protection available since | 6 July 2005 12:52:03 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Lohav-S is a proxy and downloader Trojan for the Windows platform.
Troj/Lohav-S includes functionality to access the internet and communicate with a remote server via HTTP.
When first run Troj/Lohav-S copies itself to <System>\drwatson32.exe and creates the following files:
<System>\drwatson_.exe
<System>\drwatson_32.exe
The following registry entry is set, so that drwatson32.exe is run when files with extensions of EXE are opened/launched:
HKCR\exefile\shell\open\command
(default)
"<System>\drwatson32.exe" -run "%1" %*
Registry entries are created under:
HKCU\Software\LocalDateTime\
Troj/Lohav-S may also modify the following registry entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
DrWatson
