by turbostangman » Wed Jul 07, 2004 8:45 pm
Trend also found this, Troj_small.Y
Went to Sophos and they skip the "Y" and go from X-Z. But here is the skinny on "X";
Trojan.Win32.Small.i, TROJ_SMALL.XC.
A virus identity (IDE) file which provides protection is available now from the Latest virus identities section, and is incorporated into the July 2004 (3.83) release of Sophos Anti-Virus.
At the time of writing, Sophos has received just one report of this Trojan from the wild.
Troj/Small-X is a Trojan which downloads and executes EXE files from remote URLs without the user's knowledge.
The Trojan drops its downloading component (a DLL with a temporary filename and a TMP extension) in the temporary folder and creates the following registry entry to attempt to run itself on system logon:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
msmc= <Windows system>\msmc.exe
So it looks like this little booger was going out and uploading the 123946.exe file without me knowing, that is why it kept coming back.
I went and looked at X and Z and the file names for removing it are different so I am sure those are going to be different than Y.
I wonder if Micro has the info on eliminating the Small.Y virus.