Home Malware Programs Trojans Troj/Mdrop-CKL

Troj/Mdrop-CKL

Posted: February 10, 2010

Troj/Mdrop-CKL is a malicious Trojan designed to steal banking details. Troj/Mdrop-CKL uses stealth tactics to enter the PC before downloading other harmful files from the Internet. Troj/Mdrop-CKL steals financial data like credit card numbers and online banking login details by taking screen snapshots of user activity. Troj/Mdrop-CKL also downloads additional components and poses a severe security risk to computer safety.

Aliases

Trojan.Win32.Oficla (Ikarus)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\lfrt.njo
    2 %System%\rsma.tdo
    3 %System%\sdra64.exe
    4 %Temp%\1.tmp
    5 %Temp%\3.tmp
    6 %Temp%\4.tmp
    7 %Windir%\Temp\6.tmp

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
Loading...