Threat Database Trojans Troj/MDrop-ELD

Troj/MDrop-ELD

By JubileeX in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 10
First Seen: August 28, 2012
Last Seen: April 15, 2022
OS(es) Affected: Windows

Troj/MDrop-ELD, also known as Disttrack or Shamoon, is a Trojan designed to steal information and destroy operations on a certain network.

Troj/MDrop-ELD attempts to overwrite numerous files in the 'UserProfile' areas of the disk, killing a variety of .bmp, .lnk, .cab , .ini, and other file types with a corrupt JPG (JFIF) file. Troj/MDrop-ELD also attempts to overwrite the MBR, making the affected PC not bootable. This is most probably being used to cover the source of the PC user's infection and block Data Recovery on the infected computer system.

SpyHunter Detects & Remove Troj/MDrop-ELD

File System Details

Troj/MDrop-ELD may create the following file(s):
# File Name MD5 Detections
1. trksvr.exe b14299fd4d1cbfb4cc7486d978398214 3
2. trksvr.exe d214c717a357fe3a455610b197c390aa 2
3. C:\windows\system32\trksvr.exe
4. The writer(6).exe b128376f2d45cfdf21035d3029ef0d6c 0

Registry Details

Troj/MDrop-ELD may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrkSvr\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrkSvr\Enum
HKLM\SYSTEM\CurrentControlSet\Services\lanmanworkstation
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TrkSvr

Trending

Most Viewed

Loading...