Home Malware Programs Trojans Trojan-Dropper.Win32.Mudrop.asj

Trojan-Dropper.Win32.Mudrop.asj

Posted: April 14, 2011

Trojan-Dropper.Win32.Mudrop.asj is a mischievous trojan infection that may activate malicious system processes and conceal itself from firewall and anti-virus software. Trojan-Dropper.Win32.Mudrop.asj runs in the background and enables remote access to the affected computer system. Trojan-Dropper.Win32.Mudrop.asj is able to infect system files on the computer. Trojan-Dropper.Win32.Mudrop.asj can control your web browsing activity as well as obtain access to your personal details.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\Microsoft\Windows Media\9.0\WMSDKNSD.XML
    2 %Temp%\nbfile0.exe
    3 %Temp%\nbfile1.exe
    4 c:\1.vbs
    5 c:\newsetup.vbs

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\AllowHKEY_CURRENT_USER\Software\Microsoft\MedHKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\HealthHKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{12F31C2E-1EDE-4A43-B431-E92F72CCD901}HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{FDF55593-CEEB-4B48-827E-1EA70182E8B1}HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\TasksHKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\Tasks\NowPlayingHKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\ProxySettingsHKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\ProxySettings\HTTPHKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\ProxySettings\MMSHKEY_CURRENT_USER\Software\Microsoft\Windows Script HostHKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\SettingsHKEY..\..\..\..{RegistryKeys}iaPlayer\Preferences\ProxySettings\RTSP
Loading...