3/4: Pushu-Gen Trojan Family Create Files
Troj/Pushu-Gen is a family of Trojans for the Windows platform.
When members of Troj/Pushu-Gen are installed one of the following files is usually created:
Windows\system32\drivers\ip6fw.sys
Windows\system32\drivers\netdtect.sys
Windows\system32\drivers\secdrv.sys
These files may be registered as a new system driver service named for example "Restore", "Ip6Fw", "NetDetect" or "Secdrv". Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\ When members of Troj/Pushu-Gen are installed the following file is also usually created:
Windows\system32\drivers\runtime.sys
More information can be found at this Sophos page.
