Home Malware Programs Trojans Troj/MDrop-ELD

Troj/MDrop-ELD

Posted: August 28, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 23
First Seen: August 28, 2012
Last Seen: April 15, 2022
OS(es) Affected: Windows

Troj/MDrop-ELD, also known as Disttrack or Shamoon, is a Trojan generated to steal data and damage operations on a particular network. Troj/MDrop-ELD strives to overwrite the Master Boot Record (MBR) on the affected computer system, which would make it impossible to boot the PC. Troj/MDrop-ELD also substitutes files on the hard drive, substituting certain image and system file types with a corrupt JPG (JFIF) file. Troj/MDrop-ELD aims at collecting information about the targeted PC.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



The writer(6).exe File name: The writer(6).exe
Size: 989.19 KB (989191 bytes)
MD5: b128376f2d45cfdf21035d3029ef0d6c
Detection count: 43
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 29, 2012
trksvr.exe File name: trksvr.exe
Size: 989.18 KB (989184 bytes)
MD5: b14299fd4d1cbfb4cc7486d978398214
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 29, 2012
trksvr.exe File name: trksvr.exe
Size: 989.18 KB (989184 bytes)
MD5: d214c717a357fe3a455610b197c390aa
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 29, 2012
C:\windows\system32\trksvr.exe File name: C:\windows\system32\trksvr.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrkSvrHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrkSvr\EnumHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrkSvr\SecurityHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanworkstation
Loading...