









 |
W32/Murlo.MB Trojan
| Name |
W32/Murlo.MB Trojan |
| Aliases |
TR/Dldr.Murlo.MB, W32.Mandaph, Worm.Win32.Agent.af |
| Discovered on |
May 08, 2008 |
Virus Information - W32/Murlo.MB Trojan:
W32/Murlo.MB is a trojan. The trojan will infect Windows systems.
Upon execution, the trojan drops the following files
spools.exe in drivers folder located under Windows System folder NdisHlpw.sys in drivers folder located under Windows System folder lsass.exe in the current user temp folder 5A09.tmp in the current user temp folder CC2.tmp in the current user temp folder
The trojan modifies registry at the following locations to load itself during each startup.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services 
|