English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Trojan-Downloader.Win32.Small.yx

Detected Dec 22 2004 11:53 GMT
Released Dec 22 2004 11:53 GMT
Published Aug 09 2005 11:39 GMT

Technical Details

This Trojan program downloads files via the Internet without the knowledge or consent of the user.

The Trojan itself is a Windows PE EXE file approximately 3KB in size, packed using FSG. The unpacked file is approximately 12KB in size.

It downloads the following files from the server:

dktibs.exe
mstask1.exe
mstask2.exe
mstask3.exe
systime.exe
test
toolbar.exe

The Trojan then copies itself to the Windows system and root directories and launches itself for execution.

It also changes the "%System%\drivers\etc\hosts" file by appending the text below, blocking access to these sites.

127.0.0.3 aaasexypics.com
127.0.0.3 allforadult.com
127.0.0.3 autoescrowpay.com
127.0.0.3 awmdabest.com
127.0.0.3 counter.sexmaniack.com
127.0.0.3 iframe.biz
127.0.0.3 newiframe.biz
127.0.0.3 n-glx.s-redirect.com
127.0.0.3 pizdato.biz
127.0.0.3 sexfiles.nu
127.0.0.3 vesbiz.biz
127.0.0.3 virgin-tgp.net
127.0.0.3 www.aaasexypics.com
127.0.0.3 www.allforadult.com
127.0.0.3 www.autoescrowpay.com
127.0.0.3 www.awmdabest.com
127.0.0.3 www.iframe.biz
127.0.0.3 www.newiframe.biz
127.0.0.3 www.pizdato.biz
127.0.0.3 www.sexfiles.nu
127.0.0.3 www.vesbiz.biz
127.0.0.3 www.virgin-tgp.net
127.0.0.3 x.full-tgp.net

Small.yx terminates processes where the names contain the text strings listed below:

actalert.exe 
alchem.exe 
bargains.exe 
bdl74125.exe 
bitmap.tmp 
exdl.exe 
exploit.exe 
file.exe 
fnnmqi.exe 
fucker.exe 
host32.exe 
iinstall.exe 
Installer2.exe 
intron.exe 
intronet.exe 
ir.exe 
istsvc.exe 
loadclean.exe 
lpt.exe 
msxmidi.exe 
optimize.exe 
PEPEmsPE.exe 
powerscan.exe 
printer.exe 
printer32.exe 
services.exe 
sidefind.exe 
s-PEPE.exe 
telnet.exe 
teur.exe 
ttgkirnl.exe 
twink64.exe 
usb.exe 
Winad.exe 
WinClt.exe 
winmm64.exe 
ykyrtws.exe

Bookmark and Share
Share
Trojan-Downloader

Programs classified as Trojan-Downloader download and install new versions of malicious programs, including Trojans and AdWare, on victim computers. Once downloaded from the Internet, the programs are launched or included on a list of programs which will run automatically when the operating system boots up.

Information about the names and locations of the programs which are downloaded are in the Trojan code, or are downloaded by the Trojan from an Internet resource (usually a web page).

This type of malicious program is frequently used in the initial infection of visitors to websites which contain exploits.


Other versions

Aliases

Trojan-Downloader.Win32.Small.yx (Kaspersky Lab) is also known as:

  • Trojan-Downloader.Win32.Small.aeh (Kaspersky Lab)
  • TrojanDownloader.Win32.Small.yx (Kaspersky Lab)
  • Mal/DownLdr-O (Sophos)
  • Trojan.Downloader.Small-306 (ClamAV)
  • W32/Downloader.BXM (FPROT)
  • TrojanDownloader:Win32/Harnig (MS(OneCare))
  • Trojan.DownLoader.929 (DrWeb)
  • Generic.Malware.dld!!g.B65C6C8D (BitDef7)
  • Generic.Malware.dld!!g.E258EA00 (BitDef7)
  • TR/Dldr.Small.YX.A (AVIRA)
  • Downloader.Trojan (NAV)
  • Suspicious_Gen.MNHQ (Norman)
  • Suspicious_Gen.MNSK (Norman)
  • Trojan-Downloader.Win32.Small.yx [AVP] (FSecure)