Sophos

Troj/Mdrop-BOZ

Aliases
  • Trojan-Dropper.Win32.MultiJoiner.13.k
  • Win32/TrojanDropper.Agent.AGE
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Included in our products from May 2007 (4.17)
Protection available since 28 March 2007 20:45:48 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Mdrop-BOZ is a Trojan dropper for the Windows platform.

Troj/Mdrop-BOZ contains functionality to disable some anti-virus applications.

When Troj/Mdrop-BOZ is installed the following files are created:

<Temp>\RarSFX0\bilder.exe
<Temp>\RarSFX0\foto.exe
<Temp>\RarSFX0\fotos.bat
<Temp>\RarSFX0\fotos.pif
<Temp>\RarSFX0\photo.jpg
<Temp>\TMP104_AX5.dat

The files bilder.exe and fotos.bat are also detected as Troj/Mdrop-BOZ. The file foto.exe is detected as Troj/Dropper-OC. The files fotos.pif, TMP104_AX5.dat and photo.jpg are not inherently malicious.

When first run, Troj/Mdrop-BOZ may display the image file photo.jpg.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer