Sophos

Troj/Multidr-EG

Aliases
  • MultiDropper-BN
  • TROJ_DROPPER.DU
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Included in our products from October 2005 (3.98)
Protection available since 31 August 2005 08:24:09 (GMT)
Last updated 1 September 2005 10:20:04 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Multidr-EG is a Trojan for the Windows platform.

When Troj/Multidr-EG is installed the following files may be created:

<Program Files>\Media Access\Info.txt
<Program Files>\Media Access\MediaAccC.dll
<Program Files>\Media Access\MediaAccK.exe
<Program Files>\Media Access\MediaAccess.exe
<System>\setup32.exe
<System>\msdirectx.sys
<Temp>\mss.exe
<Temp>\oddworldz.exe

The files mss.exe and setup32.exe are detected as W32/Rbot-Fam.
The file msdirectx.sys is detected as Troj/NtRootK-F.

The files Info.txt, MediaAccC.dll, MediaAccK.exe and MediaAccess.exe are non-malicious.

The following registry entry is created to run oddworldz.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
oddworldz.exe
<Temp>\oddworldz.exe

The file MediaAccess.exe is registered as a COM object, creating registry entries under:

HKCR\CLSID\(1E5F0D38-214B-4085-AD2A-D2290E6A2D2C)
HKCR\MediaAccess.Installer\
HKCR\TypeLib\(15696AE2-6EA4-47F4-BEA6-A3D32693EFC7)

Registry entries are created under:

HKLM\SOFTWARE\Media Access\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer