Home Malware Programs Trojans Generic Dropper.ru

Generic Dropper.ru

Posted: April 6, 2010

Generic Dropper.ru is a generic detection for a Trojan that will alter the system registry and INI files of the victim's computer to run on system start-up. Generic Dropper.ru will try to connect to a remote server to download more threats. Remove Generic Dropper.ru before it wreaks havoc on your PC.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %WINDIR%\system32\lowsec\local.ds
    2 %WINDIR%\system32\lowsec\user.ds
    3 %WINDIR%\system32\sdra64.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}EnableFirewall="0×00000000"[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Shared Access\Parameters\FirewallPolicy\StandardProfile\][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Shared Access\Parameters\FirewallPolicy\StandardProfile\]
Loading...