Home Malware Programs Trojans MultiDropper-SK

MultiDropper-SK

Posted: May 14, 2009

MultiDropper-SK is a trojan downloader created to drop multiple types of malware on a victims computer. MultiDropper-SK will use an icon similar to Java SDK installer with filename avg.exe to deceive computer users about its identity. Pretty sneaky, huh?

File System Modifications

  • The following files were created in the system:
    # File Name
    1 C:\Documents and Settings\[user's folder]\Application Data
    2 C:\Program Files %systemroot%\Temp\

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "avg"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce "Cleanup"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run "Macromedia Flash Player Addon"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run "Update.exe"
Loading...