Sophos

Troj/Mdrop-BQE

Aliases
  • Trojan-Dropper.Win32.VB.wi
  • DR/KeyLogger.O
  • W32.Amsa
  • W32/Dropper.ESQ
  • Win32/SecondSight
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from March 2008 (4.27)
Protection available since 4 February 2008 18:36:56 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Mdrop-BQE is a Trojan for the Windows platform.

Troj/Mdrop-BQE usually can be located with the filename activexdebugger32.exe.

When first run the Trojan copies itself to the Windows system folder and creates the following files:

<Temp>\nesneler.exe
<System>\kmon.ocx
<System>\ktkbdhk3.dll
<System>\mswinsck.ocx
<System>\pac.exe
<System>\scrrntr.dll

The file kmon.ox is detected as Keyboard Monitor potentially unwanted keylogging application and the file pac.exe is detected as W32/Amca-A.

The following registry entry is changed to run Troj/Mdrop-BQE on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe <original Trojan filename>

Registry entries are created under:

HKCR\MSWinsock.Winsock

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer