Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | October 2005 (3.98) |
| Protection available since | 27 August 2005 17:22:37 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Mosuck-A is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.
When Troj/Mosuck-A is first run it moves itself to the Windows folder with the filename xpupdater02.exe, with the hidden and system attributes set and creates the following registry entries to run itself on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
xp32win
<Windows>\xpupdater02.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
xp32win
<Windows>\xpupdater02.exe /RunOnce
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
xp32win
<Windows>\xpupdater02.exe
The following registry entry is set or modified, so that xpupdater02.exe is run when files with extensions of EXE are opened/launched:
HKCR\exefile\shell\open\command
(Default)
<Windows>\xpupdater02.exe "%1" %*
Harmless files may be created in the Windows folder as follows:
<Windows>\<variable>holidays (1).JPG
<Windows>\<variable>holidays (2).JPG
<Windows>\<variable>holidays (3).jpg
<Windows>\<variable>holidays (4).jpg
<Windows>\zlogitmm
<Windows>\ActiveXExe\<variable>.exe
