Troj/Fudge-A is a Trojan for the Windows platform.
When Troj/Fudge-Ais installed the following files are created:
<Temp>\gur3.exe
<System>xxxxxxxx.dll
where xxxxxxxx.dll is a random filename
The following registry entries are created to run code exported by xxxxxxxx.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xxxxxxxx
DllName
xxxxxxxx.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xxxxxxxx
Impersonate
0x00000000
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\windyi32
Startup
kfpsNf
Registry entries are created under:
HKLM\SOFTWARE\Microsoft\MSSMGR
}