Troj/Dropper-AA

Category: Viruses and Spyware
Type: Trojan
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Dropper-AA is a dropper Trojan.

Troj/Dropper-AA will drop SYSW.DLL into the Windows folder and run it.

In order to run the dropped file automatically each time Windows starts, Troj/Dropper-AA will set the following registry entries:

HKCR\CLSID\(RND-CLSID)\InProcServer32
(default)
sysw.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ ShellServiceObjectDelayLoad
System
(RND-CLSID)

where (RND-CLSID) is a randomly generated GUID.

A sample of Troj/Dropper-AA is known to drop Troj/LdPinch-AO.

download Try Sophos products for free
Download now