TROJ_DROPPR.AVR
Windows 2000, Windows XP, Windows Server 2003

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan may be dropped by other malware. It may be unknowingly downloaded by a user while visiting malicious websites.
TECHNICAL DETAILS
Arrival Details
This Trojan may be dropped by other malware.
It may be unknowingly downloaded by a user while visiting malicious websites.
Installation
This Trojan drops and executes the following files:
- %Program Files%\Common Files\System\msadc\msadcr.dll
(Note: %Program Files% is the default Program Files folder, usually C:\Program Files.)
Autostart Technique
This Trojan creates the following registry entries to enable automatic execution of dropped component at every system startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Winlogon\
Notify\msadcr
Logon = "WlDimsStartup"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Winlogon\
Notify\msadcr
DLLName = "%Program Files%\Common Files\System\msadc\msadcr.dll"