Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | September 2005 (3.97) |
| Protection available since | 14 July 2005 05:42:35 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Mkmoose-A is a Trojan for the Windows platform.
Troj/Mkmoose-A will inject code into other running processes in order to run without being noticed. It will contact a remote URL to report infection and to download files.
The Trojan also has backdoor functionality which will allow a remote user to perform the following activities:
Create/delete files and folders
Run commands
Upload/download files
Troj/Mkmoose-A moves itself to the Windows system folder as pathex.exe and position.exe and will create the following registry entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
""
"<System>\pathex.exe"
