Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | November 2004 (3.87) |
| Protection available since | 4 October 2004 13:20:39 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Dloader-EK is a downloading Trojan.
The Trojan attempts to download several files, each from up to three preconfigured URLs, to the Windows system folder. If no files could be downloaded, the Trojan will try again later.
Once the files have been downloaded, they are executed.
In order to ensure that it is run at system startup, the Trojan creates the following registry entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
cmrss = "C:\Windows\System32\crmss.exe"
Troj/Dloader-EK also copies itself to the Windows system folder.
