Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | August 2007 (4.20) |
| Protection available since | 4 July 2007 18:16:10 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/SCLog-AG is a Trojan for the Windows platform.
When first run Troj/SCLog-AG copies itself to <System>\HackMuFpt.exe and creates the file <System>\HackMuFpt.dll.
The following registry entry is created to run HackMuFpt.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HackMuFpt
<System>\HackMuFpt.exe
The following registry entries are created to run code exported by HackMuFpt.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\HackMuFpt
DllName
HackMuFpt.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\HackMuFpt
Impersonate
0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\HackMuFpt
Startup
WLEvtStartup
