TROJ_MEREDROP.H
HEUR:Trojan.Win32.Generic (Kaspersky), Win32/Kryptik.AKES (ESET), Trojan.Win32.Meredrop (Sunbelt)
Windows

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It deletes itself after execution.
TECHNICAL DETAILS
54,784 bytes
EXE
08 Apr 2009
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following files:
- %System%\config\rqnazudm.sav
(Note: %System% is the Windows system folder, which is usually C:\Windows\System32.)
Other System Modifications
This Trojan adds the following registry keys:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\.serial
Other Details
This Trojan deletes itself after execution.