Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 5 July 2007 15:43:03 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/SCLog-AJ is a Trojan for the Windows platform.
When first run Troj/SCLog-AJ copies itself to <System>\smcss.exe and creates the file <System>\smcss.dll.
The following registry entry is created to run smcss.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
smcss
<System>\smcss.exe
The following registry entries are created to run code exported by smcss.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\smcss
DllName
smcss.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\smcss
Impersonate
0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\smcss
Startup
WLEvtStartup
