Troj/Mdrop-ERL

Category: Viruses and Spyware Protection available since:22 Nov 2012 17:20:38 (GMT)
Type: Trojan Last Updated:22 Nov 2012 17:20:38 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Mdrop-ERL exhibits the following characteristics:

File Information

Size
97K
SHA-1
bfeb0de4add7143291371c5e8954c9352100531d
MD5
2aa3a2bb41c6bf1dccad03c144c1fd67
CRC-32
5829dcde
File type
Windows executable
First seen
2012-11-22

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Application Data\WinDefender\WinDefender.Exe
Dropped Files
  • c:\Documents and Settings\test user\Application Data\OykrR.vbs
    Size
    437
    SHA-1
    e1b3b6d406867e7a3c7fa98b82683bbd14b40509
    MD5
    b86cd08bb087d7b301ed11e042b60f8f
    CRC-32
    cd08bca3
    File type
    Visual Basic Script
    First seen
    2012-09-01
Registry Keys Created
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    WinDefender
    "c:\Documents and Settings\test user\Application Data\WinDefender\WinDefender.Exe"
Registry Keys Modified
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
    DisableTaskMgr
    0x00000001
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
    Hidden
    0x00000002
Processes Created
  • c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
  • c:\windows\system32\wscript.exe
IP Connections
  • 76.30.155.251:1337

download Try Sophos products for free
Download now