Trojan.Shadu. The dropped file has is named as a.exe. More information about this can be obtained here.And, another one is a trojan which drops a rootkit. The trojan dropper drops a file named
Gop.exe which installs a rootkit. AntiVir detects Gop.exe as TR/Small.DBY.DB. The rootkit driver that's installed by Gop.exe is named as vdo_4e2b-928.sys (generally, it will be named as vdo_[random_numbers]-[random_numbers].sys) and belongs to Win32.Tibs family. More information about this can be obtained here.
0 comments:
Post a Comment