Sophos

Troj/Mdrop-RG

Aliases
  • Trojan-Dropper.Win32.Delf.rg
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 24 January 2006 22:16:39 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Mdrop-RG is a dropper Trojan for the Windows platform.

When first run Troj/Mdrop-RG copies itself to <Windows>\huysosat.exe and creates the following files:

<User>\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk
\asa1.exe
\asa2.exe
\asa3.exe

In typical samples of Troj/Mdrop-RG the files dropped are as follows:
asa1.exe is detected as Dial/Dialer-MY
asa2.exe is detected as Dial/Chivio-R
asa3.exe is detected as Dial/Dialer-MZ

The following registry entry is created to run huysosat.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
huySosat
<Windows>\huysosat.exe

The following registry entry is set:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Start_ShowNetConn_ShouldShow
42

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer