Home Malware Programs Trojans Trojan Dropper.generic2.mnz

Trojan Dropper.generic2.mnz

Posted: November 14, 2011

Trojan Dropper.generic2.mnz is a computer Trojan that may load malicious files to collect data from an infected PC. A remote hacker may utilize Trojan Dropper.generic2.mnz to collect data from a vulnerable system which could easily lead to identity theft. Trojan Dropper.generic2.mnz is known to be data collection malware. To prevent data from being stolen or compromised it is highly suggestive that Trojan Dropper.generic2.mnz be detected and removed with a spyware removal program.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



SystemPropertiesAdvancedViewer.exe File name: SystemPropertiesAdvancedViewer.exe
File type: Executable File
Mime Type: unknown/exe
B6232F3A42A.exe File name: B6232F3A42A.exe
File type: Executable File
Mime Type: unknown/exe
COHServer.exe File name: COHServer.exe
File type: Executable File
Mime Type: unknown/exe
csrss.exe File name: csrss.exe
File type: Executable File
Mime Type: unknown/exe
nvvsvc.exe File name: nvvsvc.exe
File type: Executable File
Mime Type: unknown/exe
Music System.exe File name: Music System.exe
File type: Executable File
Mime Type: unknown/exe
igfxtray.exe File name: igfxtray.exe
File type: Executable File
Mime Type: unknown/exe
aruqt.exe File name: aruqt.exe
File type: Executable File
Mime Type: unknown/exe
1930.exe File name: 1930.exe
File type: Executable File
Mime Type: unknown/exe
svchos.exe File name: svchos.exe
File type: Executable File
Mime Type: unknown/exe
tplsub700jk.exe File name: tplsub700jk.exe
File type: Executable File
Mime Type: unknown/exe
Security Solution.exe File name: Security Solution.exe
File type: Executable File
Mime Type: unknown/exe
mscj2.exe File name: mscj2.exe
File type: Executable File
Mime Type: unknown/exe
winsvc.exe File name: winsvc.exe
File type: Executable File
Mime Type: unknown/exe
bswuwntossplhd.exe File name: bswuwntossplhd.exe
File type: Executable File
Mime Type: unknown/exe
ntdel.exe File name: ntdel.exe
File type: Executable File
Mime Type: unknown/exe
KillEXE.exe File name: KillEXE.exe
File type: Executable File
Mime Type: unknown/exe
hkicmd.exe File name: hkicmd.exe
File type: Executable File
Mime Type: unknown/exe
acleaner.exe File name: acleaner.exe
File type: Executable File
Mime Type: unknown/exe
rqcovth.exe File name: rqcovth.exe
File type: Executable File
Mime Type: unknown/exe
lde1.exe File name: lde1.exe
File type: Executable File
Mime Type: unknown/exe
realupgrade.exe File name: realupgrade.exe
File type: Executable File
Mime Type: unknown/exe
winhelp.exe File name: winhelp.exe
File type: Executable File
Mime Type: unknown/exe
facebook-pic0009696904901.exe File name: facebook-pic0009696904901.exe
File type: Executable File
Mime Type: unknown/exe
KB11657984.exe File name: KB11657984.exe
File type: Executable File
Mime Type: unknown/exe
arking.exe File name: arking.exe
File type: Executable File
Mime Type: unknown/exe
uetcilehmof.exe File name: uetcilehmof.exe
File type: Executable File
Mime Type: unknown/exe
SynNglp.exe File name: SynNglp.exe
File type: Executable File
Mime Type: unknown/exe
wnzip32.exe File name: wnzip32.exe
File type: Executable File
Mime Type: unknown/exe
thunder.exe File name: thunder.exe
File type: Executable File
Mime Type: unknown/exe
TCodecLite.exe File name: TCodecLite.exe
File type: Executable File
Mime Type: unknown/exe
sXeInjectedSetup.8.9.exe File name: sXeInjectedSetup.8.9.exe
File type: Executable File
Mime Type: unknown/exe
nvsvc32.exe File name: nvsvc32.exe
File type: Executable File
Mime Type: unknown/exe
GoogleDownload.exe File name: GoogleDownload.exe
File type: Executable File
Mime Type: unknown/exe
gabpath.exe File name: gabpath.exe
File type: Executable File
Mime Type: unknown/exe
CurseClient.exe File name: CurseClient.exe
File type: Executable File
Mime Type: unknown/exe
CronikalNewLouncher.exe File name: CronikalNewLouncher.exe
File type: Executable File
Mime Type: unknown/exe
flash_player_installer.exe File name: flash_player_installer.exe
File type: Executable File
Mime Type: unknown/exe
geurge.exe File name: geurge.exe
File type: Executable File
Mime Type: unknown/exe
tskhelp32.exe File name: tskhelp32.exe
File type: Executable File
Mime Type: unknown/exe
qaovyciydw.exe File name: qaovyciydw.exe
File type: Executable File
Mime Type: unknown/exe
NTsrv.exe File name: NTsrv.exe
File type: Executable File
Mime Type: unknown/exe
malware.exe File name: malware.exe
File type: Executable File
Mime Type: unknown/exe
2025.exe File name: 2025.exe
File type: Executable File
Mime Type: unknown/exe
iexplore.exe File name: iexplore.exe
File type: Executable File
Mime Type: unknown/exe

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ntuser RUNNING PROGRAM\MagicISO.exeHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ restorer32_aHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\molochaHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ anhaoHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ DelayLoadHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\USERINIT\ userinitHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ hgcheckHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINDOWS\APPINIT_DLLS\ AppInit_DLLsHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows UpdateHKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Microsoft Windows InstallerHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ autoload
Loading...