TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
TROJ_DROPPER.SPX
Technical Details

File type: PE

Memory resident:  No

Size of malware: 167,102 Bytes

Initial samples received on: May 7, 2009

Related toTROJ_AGENT.NICE


Payload 1: Executes another malicious file



Details:

This Trojan may be downloaded from remote sites.

It is a fake/Trojanized Windows 7 Release Candidate (RC) build.

It is a self extracting executable that contains two executables: one is the original Windows 7 RC build named SETUP.EXE, and the other is CODEC.EXE. Trend Micro detects CODEC.EXE as TROJ_AGENT.NICE.

When an unsuspecting user executes the Trojanized setup file, the embedded malware is also executed. As a result, malicious routines of the embedded file are exhibited on the affected system.

It runs on Windows 98, ME, NT, 2000, XP, and Server 2003.

Analysis By: Roland Dela Paz

Revision History:

First pattern file version: 6.116.01
First pattern file release date: May 07, 2009

For additional information about this threat, see:
Overview
Solution

Search a new malware

Tell us how we did. Take our quick survey.