Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | October 2005 (3.98) |
| Protection available since | 31 August 2005 08:24:09 (GMT) |
| Last updated | 1 September 2005 10:20:04 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Multidr-EG is a Trojan for the Windows platform.
When Troj/Multidr-EG is installed the following files may be created:
<Program Files>\Media Access\Info.txt
<Program Files>\Media Access\MediaAccC.dll
<Program Files>\Media Access\MediaAccK.exe
<Program Files>\Media Access\MediaAccess.exe
<System>\setup32.exe
<System>\msdirectx.sys
<Temp>\mss.exe
<Temp>\oddworldz.exe
The files mss.exe and setup32.exe are detected as W32/Rbot-Fam.
The file msdirectx.sys is detected as Troj/NtRootK-F.
The files Info.txt, MediaAccC.dll, MediaAccK.exe and MediaAccess.exe are non-malicious.
The following registry entry is created to run oddworldz.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
oddworldz.exe
<Temp>\oddworldz.exe
The file MediaAccess.exe is registered as a COM object, creating registry entries under:
HKCR\CLSID\(1E5F0D38-214B-4085-AD2A-D2290E6A2D2C)
HKCR\MediaAccess.Installer\
HKCR\TypeLib\(15696AE2-6EA4-47F4-BEA6-A3D32693EFC7)
Registry entries are created under:
HKLM\SOFTWARE\Media Access\
