TROJ_MDROPPER.CD
Exploit:Win32/CVE-2012-0158 (Microsoft), Trojan.Mdropper (Symantec), Exp/20120158-A (Sophos)
Windows 2000, Windows XP, Windows Server 2003

Threat Type: Trojan
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
TECHNICAL DETAILS
186,864 bytes
RTF
Yes
15 Aug 2012
Arrival Details
This Trojan arrives as an attachment to email messages spammed by other malware/grayware or malicious users.
Installation
This Trojan drops and executes the following files:
- %User Temp%\WINWORD.EXE - detected as TSPY_FLAME.M
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
Dropping Routine
This Trojan takes advantage of the following software vulnerabilities to drop malicious files:
NOTES:
Upon execution, this Trojan drops and opens a document file to hide its malicious routines from the user.
SOLUTION
9.200
9.326.08
15 Aug 2012
9.327.00
15 Aug 2012
Step 1
For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you to allow full scanning of your computer.
Step 2
Remove the malware/grayware file that dropped/downloaded TROJ_MDROPPER.CD