Home Malware Programs Trojans Drorar

Drorar

Posted: March 28, 2006

Drorar is a trojan that records user keystrokes and steals computer information. It silently transfers gathered data to predetermined remote servers. Drorar registers itself as a computer service called MSDCSRV32 and automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 mssrv.exe
    2 sclureg32a.dll
    3 setup32set.ini
    4 svchost.exe
    5 winsock_32a.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesWinSock2fcmail_tcpipdogPathName=%Windir%winsock_32a.dll
Loading...