Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 9 January 2008 02:12:13 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Pushu-F is a Trojan for the Windows platform.
When Troj/Pushu-F is installed it creates the file <System>\drivers\runtime.sys. The file runtime.sys is detected as Troj/Pushu-Gen.
The file runtime.sys is registered as a new system driver service named "runtime". Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\runtime\
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RUNTIME\
The Trojan also replaces <System>\drivers\secdrv.sys with its own copy. This file is detected as Troj/Pushu-Gen. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\SecDrv\
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SECDRV\
Troj/Pushu-F also creates a file <Root>\<random characters>.exe. This file is detected as Troj/Pushu-E.
