Sophos

Troj/Mdrop-BUW

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from October 2008 (4.34)
Protection available since 21 August 2008 14:16:29 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Mdrop-BUW is a Trojan for the Windows platform.

When Troj/Mdrop-BUW is installed it creates a randomly named .sys file <System>\drivers\<randomname>.sys.

The file <randomname>.sys is detected as Troj/Pushdo-Q.

The file <randomname>.sys is registered as a new system driver service named "Xcf47". Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\<randomname>

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer