Home Malware Programs Trojans Trojan.Mpddoser

Trojan.Mpddoser

Posted: June 28, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 25
First Seen: June 28, 2012
OS(es) Affected: Windows

Trojan.Mpddoser is a Trojan that opens a back door on the infected computer. Once executed, Trojan.Mpddoser modifies the particular registry entry. Trojan.Mpddoser then copies itself to the certain location and runs itself from the new location. Trojan.Mpddoser also creates the specific registry entry so that it can run automatically every time you Windows. Trojan.Mpddoser then creates the specific mutex 'IPK-MPMutex' so that only one instance is executed on the PC. Trojan.Mpddoser connects to the command-and-control (C&C) server and transfers information to it. Trojan.Mpddoser also gain instructions created by attackers from command-and-control (C&C) server. Trojan.Mpddoser can download more PC threats and initiate denial-of-service attacks.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%UserProfile%\Application Data\Windefender.exe File name: %UserProfile%\Application Data\Windefender.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\shell folders\AppData = "%UserProfile%\Application Data"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Windefender" = "%UserProfile%\Application Data\Windefender.exe"
Loading...