Sophos

Troj/Small-KY

Aliases
  • TrojanDropper.Win32.Small.ky
  • W32/Bagle.dll.dr
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from November 2004 (3.87)
Protection available since 18 September 2004 16:26:30 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Small-KY will create the following registry entries in order to start automatically on user logon or computer restart:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
wpds.exe = <Windows System>\doriot.exe and

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
wpsds.exe = <Windows System>\doriot.exe

The injected DLL may attempt to download and execute components after saving them as _re_file.exe. Please note that the injected DLL is detected by Sophos Anti-Virus as Troj/Small-KV.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer