Troj/SCLog-AG is a Trojan for the Windows platform.
When first run Troj/SCLog-AG copies itself to <System>\HackMuFpt.exe and creates the file <System>\HackMuFpt.dll.
The following registry entry is created to run HackMuFpt.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HackMuFpt
<System>\HackMuFpt.exe
The following registry entries are created to run code exported by HackMuFpt.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\HackMuFpt
DllName
HackMuFpt.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\HackMuFpt
Impersonate
0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\HackMuFpt
Startup
WLEvtStartup