TROJ_DROPPER.QUZ
October 08, 2012
PLATFORM:
Windows 2000, XP, Server 2003
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:

Threat Type: Trojan
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This Trojan executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
TECHNICAL DETAILS
File Size:
109,640 bytes
File Type:
XLS
Memory Resident:
No
Initial Samples Received Date:
03 Sep 2010
Payload:
Drops files
Dropping Routine
This Trojan drops the following files:
- %User Temp%\alg.exe - detected as BKDR_SCROG.OK
- %User Temp%\EyA???EEEAr_,O.xls - non-malicious XLS file
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
It takes advantage of the following software vulnerabilities to drop malicious files:
- (MS09-067) Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (972652)
It executes the dropped file(s). As a result, malicious routines of the dropped files are exhibited on the affected system.
Other Details
More information on this vulnerability can be found below: