Troj/Dedler-A is a downloader Trojan which attempts to download executable files from a remote location and run them.
When first run Troj/Dedler-A copies itself to the Windows System32 folder as SMRSS.EXE and adds its pathname to one of the following new registry entries
to run SMRSS.EXE automatically on startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ActiveXUpdate
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MicrosoftOEM
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SoundControl
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\OfficeGuardUI