Sophos

Troj/Mdrop-QA

Aliases
  • Trojan-Dropper.Win32.Agent.age
  • Trojan-Dropper.Win32.Agent.aay
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Included in our products from April 2006 (4.04)
Protection available since 21 February 2006 09:21:41 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Mdrop-QA is a multi-dropper Trojan for the Windows platform.

When run Troj/Mdrop-QA creates the following files:

b1.exe
fotos.bat
fotos.pif
outlook.exe
win.exe
<Temp>\3-Datei.exe
<Temp>\backdoor.log
<Temp>\dc.exe
<Program Files>\Outlook Express\1-Outlook.exe

b1.exe is a JPG extractor which run when creates the file b1.jpg. Both the files b1.exe and b1.jpg may be safely deleted.

fotos.pif and backdoor.log may be safely deleted.

3-Datei.exe is also detected as Troj/Mdrop-QA.

fotos.bat and win.exe are detected as Troj/Killav-AY.

The files outlook.exe, 1-Outlook.exe and dc.exe are detected as Troj/Rasdoor-C.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer