Sophos

Troj/Torpig-AT

Aliases
  • Trojan-Spy.Win32.Small.dg
  • Win32/TrojanDropper.Small.NDG
  • Trojan.Anserin
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2006 (4.07)
Protection available since 28 April 2006 20:53:14 (GMT)
Last updated 26 May 2006 09:41:30 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Torpig-AT is a Trojan for the Windows platform.

When Troj/Torpig-AT is installed the following files are created:

<Common Files>\Microsoft Shared\Web Folders\ibm00001.dll
<Common Files>\Microsoft Shared\Web Folders\ibm00001.exe
<Common Files>\Microsoft Shared\Web Folders\ibm00002.dll
<Common Files>\Microsoft Shared\Web Folders\ibm00003.exe

The following registry entry is created to run ibm00001.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
shell
<Common Files>\Microsoft Shared\Web Folders\ibm00001.exe

The following registry entry is changed to run ibm00001.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
explorer.exe <many spaces> "<Common Files>\Microsoft Shared\Web
Folders\ibm00001.exe"

(The default value for this registry entry is "Explorer.exe" which causes the Microsoft file <Windows folder>\Explorer.exe to be run on startup.)

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer