Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 20 February 2006 21:56:48 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Goldun-BX is a Trojan for the Windows platform.
The Trojan attempts to steal login details and block access to anti-virus related web and FTP sites. Troj/Goldun-BX is a Trojan for the Windows platform.
The Trojan attempts to steal login details and block access to anti-virus related web and FTP sites.
When Troj/Goldun-BX is installed the following files are created:
<Windows system folder>\directout.sys
<Windows system folder>\directut.dll
The file directout.sys is detected as Troj/Haxdor-Gen and the file directut.dll is detected as Troj/Goldun-BX.
The following registry entries are created to run code exported by directut.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\directut
DllName
directut.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\directut
Startup
directut
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\directut
Impersonate
1
