Summary

Summary
Action
More Information
| Detected by | All Sophos products |
|---|---|
Action

Summary
Action
More Information
Please read the instructions for removing Trojans.
You will also need to edit the following registry key, if it is present.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE key:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\666
and remove the 666 reference if it is present.
Close the registry editor and reboot your computer.
More Information
Troj/Pipes is a backdoor Trojan.
When Troj/Pipes runs, the infected computer is exposed to security attacks from remote locations. Troj/Pipes copies itself to the Windows system directory to a file named SKA.EXE. It also changes the registry key
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\666
so that it runs on Windows start-up.
