Trojan.Mdropper

By GoldSparrow in Trojans | 18 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
More... More

Trojan.Mdropper Description

Since March of 2005, certain security software manufacturers have used the detection Trojan.Mdropper to indicate the presence of a specific type of Trojan on an infected computer. These kinds of Trojans can infect versions of Windows going back to Windows 95 and are characterized by their use of known vulnerabilities in the Microsoft Office Suite, particularly in Microsoft Word and Excel, to drop other kinds of malware threats on the victim’s computer. Trojan droppers like Trojan.Mdropper are designed to deliver other malware and are typically used in the early stages of a multi-component malware attack with multiple stages.

Trojan.Mdropper Trojans load themselves into the infected computer’s memory and drop executable files belonging to other, more dangerous malware threats. They are often difficult to study because they tend to be designed so that they will delete themselves after they have accomplished their task, leaving no evidence behind. The main reason Trojans like Trojan.Mdropper are used is because they can be easily disguised as DOC of XLS files (Microsoft Word and Excel documents). Although most computer users know enough to not download executable files without knowing their source, fewer computer users know that other seemingly harmless files, such as PDF, DOC and XLS files, can also be corrupted in order to deliver malware.

There are several strategies criminals use to deliver malware on their victims’ computers. Trojan droppers are among the most common delivery systems for other Trojans. They typically act as a container for other malware, usually referred to as a payload. When they are executed, they deliver this payload and install it on the victim’s computer. Most of the time, hackers use Trojan droppers like Trojan.Mdropper instead of delivering their malware directly because they are more easy to disguise and more difficult to detect as malware. In some cases, opening a corrupted DOC or XLS file will simply result in an error message, while, in other cases, an actual Microsoft Word or Excel document is opened. However, its payload will be delivered in the background, without the victim’s knowledge.

Common Symptoms Associated with Trojan.Mdropper

Trojan.Mdropper and other Trojan droppers can conceivably be used to deliver any kind of malware. These kinds of threats deliver executable files with extensions like EXE or DLL, often opening a back door into the infected computer. Trojan.Mdropper Trojans will typically cause no symptoms, except an occasional error message. However, their payload will frequently cause severe problems on the infected computer, which will alert the computer user of their presence.

Type: Trojans

How Can You Detect Trojan.Mdropper?

Trojan.Mdropper Removal Details

Trojan.Mdropper creates the following files in the system:

  • %UserProfile%\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol
  • %Temp%\Word8.0\ShockwaveFlashObjects.exd
  • %Temp%\~WRD0001.doc

Important Article Disclaimer

ESG Support Center

This entry was last updated on 08/23/12 and posted on 08/23/12. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.