Antivirus and Security Software from Sophos

Sophos blogs

Troj/Dropper-AA

Aliases
  • Trojan-Dropper.Win32.Small.ta
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 21 February 2005 09:19:04 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Dropper-AA is a dropper Trojan.

Troj/Dropper-AA will drop SYSW.DLL into the Windows folder and run it.

In order to run the dropped file automatically each time Windows starts, Troj/Dropper-AA will set the following registry entries:

HKCR\CLSID\(RND-CLSID)\InProcServer32
(default)
sysw.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ ShellServiceObjectDelayLoad
System
(RND-CLSID)

where (RND-CLSID) is a randomly generated GUID.

A sample of Troj/Dropper-AA is known to drop Troj/LdPinch-AO.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer