Sophos

Troj/Mdrop-BWC

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Included in our products from November 2008 (4.35)
Protection available since 6 October 2008 23:22:14 (GMT)
Detected by All Sophos products

Action

Please follow the instructions for removing Trojans.

User will need to manually delete the following registry value for each <Executable Name> that does not require a debugger attached.

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\<Executable Name>

More Information

Troj/Mdrop-BWC drops the file <Windows>\Debug\<Random Number>.dll which is detected as Mal/Emogen-N.

Troj/Mdrop-BWC disables security applications by creating the following registry value for each <Executable Name> it disables:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\<Executable Name>
Debugger
IFEOFILE

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer