Sophos

Troj/Dropper-MX

Aliases
  • Trojan-Downloader.Win32.Agent.bdr
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from February 2007 (4.14)
Protection available since 10 January 2007 00:20:57 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dropper-MX is a dropper Trojan for the Windows platform.

When Troj/Dropper-MX is installed the following files are created:

\(30FB7D08-056E-1033-0501-03020730002c)\Bar888.dll
\(30FB7D08-056E-1033-0501-03020730002c)\UnInstall.exe
\(30FB7D08-056E-1033-0501-03020730002c)\UnInstall.lzma
\(30FB7D08-056E-1033-0501-03020730002c)\toolbardll.lzma
\Recycled\info2
\svchosts.lzma
\unsvchosts.exe
\unsvchosts.lzma

The file unsvchosts.exe is detected as a PUA with the name CommAd, and the file Bar888.dll is detected as a PUA with the name Toolbar888. The files UnInstall.exe and info2 are not malicious. The files with .lzma extensions are archives of the above files.

Registry entries are created under:

HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Bar888

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer