Sophos

Troj/Multidr-EU

Aliases
  • Trojan-Spy.Win32.Agent.ct
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 29 November 2005 06:32:41 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Multidr-EU is a dropper Trojan for the Windows platform.

When run Troj/Multidr-EU creates the following files:

<System>\ntdll32.dll - detected by Sophos as Troj/MMThief-A
<System>\ranx.dll - detected by Sophos as Troj/Hackvan-A
<System>\god.sys - detected by Sophos as Troj/Hackvan-A
<System>\svch0st.exe - detected by Sophos as Troj/Multidr-EU
<Windows>\suniu.exe - detected by Sophos as Troj/Multidr-EU
<System>\mmdat.dat - this file may be deleted
<System>\wdata32.dll - this file may be deleted
<Windows>\123.jpg - this file may be deleted

The following registry entries are set to run Troj/Multidr-EU at startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
SVCHOST
<System>\SVCH0ST.EXE

HKCR\exefile\Shell\open\command
(default)
<System>\SVCH0ST.EXE %1 %*

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer