TROJ_DROPPR.SMAG
Windows 2000, Windows XP, Windows Server 2003
Threat Type: Trojan
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
Varies
DLL
25 May 2011
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other System Modifications
This Trojan adds the following registry entries:
HKEY_CLASSES_ROOT\PROTOCOLS\Filter\
text/html
(Default) = "Microsoft Improved HTML MIME Filter"
HKEY_CLASSES_ROOT\PROTOCOLS\Filter\
text/html
CLSID = "{random CLSID}"
HKEY_CLASSES_ROOT\CLSID\{random CLSID}\
InProcServer32
(Default) = "%User Temp%\msmonitor"
HKEY_CLASSES_ROOT\CLSID\{random CLSID}\
InProcServer32
ThreadingModel = "Apartment"
Dropping Routine
This Trojan drops the following files:
- %User Temp%\msmonitor
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)