Troj/Mdrop-CTW

Category: Viruses and Spyware Protection available since:29 Jul 2010 20:42:45 (GMT)
Type: Trojan Last Updated:29 Jul 2010 20:42:45 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Mdrop-CTW is a Trojan for the Windows platform.

Troj/Mdrop-CTW includes functionality to run automatically and access the internet and communicate with a remote server via HTTP.

Troj/Mdrop-CTW communicates via HTTP with the following locations:

irs . gov
91 . 216 . 122 . 60

When Troj/Mdrop-CTW is installed the following files are created:

<Windows>\inf\AcroIEHelper.dll
<Windows>\inf\alg.exe

The file alg.exe is registered as a new service named "WSALG2", with a display name of "Application Layer Gateway Service2". Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\WSALG2

The file AcroIEHelper.dll is registered as a COM object and Browser Helper Object (BHO) for Microsoft Internet Explorer, creating registry entries under:

HKCR\CLSID\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB}

Registry entries are created under:

HKLM\SOFTWARE\Microsoft\DownloadManager

download Try Sophos products for free
Download now