Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | November 2008 (4.35) |
| Protection available since | 6 October 2008 23:22:14 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
User will need to manually delete the following registry value for each <Executable Name> that does not require a debugger attached.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\<Executable Name>
More Information
Troj/Mdrop-BWC drops the file <Windows>\Debug\<Random Number>.dll which is detected as Mal/Emogen-N.
Troj/Mdrop-BWC disables security applications by creating the following registry value for each <Executable Name> it disables:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\<Executable Name>
Debugger
IFEOFILE
