Home Malware Programs Trojans Downloader.Dromedan

Downloader.Dromedan

Posted: October 21, 2011

Threat Metric

Threat Level: 10/10
Infected PCs: 16
First Seen: October 21, 2011
Last Seen: January 6, 2022
OS(es) Affected: Windows

Downloader.Dromedan is a dangerous Trojan that is distributed via malicious email atatachments. Downloader.Dromedan can connect to some malicious websites to download and install additional malware threats on to the infected computer. Once installed on the targeted PC, Downloader.Dromedan drops some system files and modifies the registry. Downloader.Dromedan also creates its registry entry so that it can run each time you start Windows. Downloader.Dromedan injects itself into the svchost.exe process. Remove Downloader.Dromedan immediately after detection.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%AllUsersProfile%\LOCALS~1\Temp\[RANDOM CHARACTERS].com File name: %AllUsersProfile%\LOCALS~1\Temp\[RANDOM CHARACTERS].com
File type: Command, executable file
Mime Type: unknown/com
Group: Malware file
%SystemDrive%\Documents and Settings\All Users\Local Settings\Temp\[RANDOM CHARACTERS].com File name: %SystemDrive%\Documents and Settings\All Users\Local Settings\Temp\[RANDOM CHARACTERS].com
File type: Command, executable file
Mime Type: unknown/com
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\"2600" = "%SystemDrive%\DOCUME~1\ALLUSE~1\LOCALS~1\Temp\[RANDOM CHARACTERS].com"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AA
Loading...