Sophos

Troj/Mkmoose-A

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 14 July 2005 05:42:35 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/Mkmoose-A is a Trojan for the Windows platform.

Troj/Mkmoose-A will inject code into other running processes in order to run without being noticed. It will contact a remote URL to report infection and to download files.

The Trojan also has backdoor functionality which will allow a remote user to perform the following activities:

Create/delete files and folders
Run commands
Upload/download files

Troj/Mkmoose-A moves itself to the Windows system folder as pathex.exe and position.exe and will create the following registry entry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
""
"<System>\pathex.exe"

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer