TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
TROJ_MDROPPER.BH
Overview

Malware type: Trojan

Aliases: No Alias Found

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

Low

Distribution potential:

Low

Description: 

This is Trend Micro's detection for a specially crafted .PPT file that is designed to exploit the Microsoft Office Remote Code Execution Using a Malformed Routing Slip Vulnerability.

If successfully exploited, the vulnerability could allow this Trojan to drop and execute a randomly named .EXE file detected by Trend Micro as TROJ_SMALL.CMZ, in the Windows temporary folder.

However, due to bugs in its code, this Trojan does not execute properly. It is thus unable to exploit the vulnerability and perform its intended file dropping routine.

More information on the Microsoft Office Remote Code Execution Using a Malformed Routing Slip Vulnerability can be found on the following Web page:

This Trojan may be downloaded from the Internet or dropped by other malware.

For additional information about this threat, see:
Solution
Technical Details

Description created: Aug. 19, 2006 4:04:11 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.