Sophos

Troj/Small-EX

Aliases
  • Trojan-Dropper.Win32.Small.ahg
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from February 2006 (4.02)
Protection available since 8 December 2005 03:18:45 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Small-EX is a backdoor Trojan which can be used as a proxy and is capable of downloading and executing arbitrary files.

When run Troj/Small-EX creates the file <System>\child.dll and child.dll is detected by Sophos as Troj/Small-EX.

When run Troj/Small-EX sets the following registry entries:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
(3F143C3A-1457-6CCA-03A7-7AA23B61E40F)
OLE Automation Module

HKCU\Software\Classes\CLSID\(3F143C3A-1457-6CCA-03A7-7AA23B61E40F)\InProcServer32
(default)
<System>\child.dll

Troj/Small-EX allows remote access on port 1234.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer