Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | May 2008 (4.29) |
| Protection available since | 5 April 2008 03:36:33 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/MDrop-BRI attempts to download further executable code.
At the time of writing, files downloaded by the Trojan are detected as Troj/Pushdo-Gen and Mal/Emogen-Y.
Troj/MDrop-BRI injects code into the svchost.exe process.
The following registry entry is created in order to run the Trojan on startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
advap32
<Trojan filename> /r
