Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | October 2008 (4.34) |
| Protection available since | 21 August 2008 14:16:29 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Mdrop-BUX is a Trojan for the Windows platform.
When first run Troj/Mdrop-BUX copies itself to <Temp>\_A00F18C9B.exe and creates the file <System>\__c0028830.dat.
The file __c0028830.dat is detected as Troj/BHO-GN.
The following registry entries are created to run code exported by __c0028830.dat on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c0028830
DllName
<System>\__c0028830.dat
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c0028830
Impersonate
0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c0028830
Startup
B
