English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Trojan.Win32.Small.ev

Detected Sep 06 2005 11:38 GMT
Released Mar 23 2007 09:04 GMT
Published Sep 06 2005 11:38 GMT

Technical Details

This Trojan is a Windows PE EXE file 40448 bytes in size.

Installation

Once launched, the Trojan creates the following files in the Windows system and root directories:

%System%\intell32.exe
%System%\oleext.dll
%System%\oleext32.dll
%System%\wppp.html
%Windir%\uninstIU.exe

It then registers itself in the system registry, ensuring that the Trojan file will be launched each times Windows is rebooted on the victim machine:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"intell32.exe" = "%System%\intell32.exe"

The Trojan also creates the following registry keys:

[HKCR\CLSID\{357A87ED-3E5D-437d-B334-DEB7EB4982A3}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Internet Update]

Payload

The Trojan will change the desktop configuration of the infected computer.

Trojan.Win32.Small.ev changes the following system registry key values in modify the background colour, wallpaper, and other desktop parameters.

[HKCU\Control Panel\Colors]
"Background" = "0 0 0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoActiveDesktopChanges" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"NoDispAppearancePage" = "1"
"NoDispBackgroundPage" = "1"

[HKCU\Control Panel\Desktop]
"WallpaperStyle" = "0"
"Wallpaper" = "%SystemRoot%\%System%\wppp.html" 

The Trojan causes the following wallpaper to be displayed:

It creates the following icon in the system tree:

When the mouse is passed over the icon shown above, the following message will be displayed:

Your computer is infected.

The Trojan will also cause the following message to be displayed at random intervals:

If the user double-clicks on the icon or a link created on the desktop, the Trojan will open the browser at http://www.psgu***.com/?aff=**&sub=0 and may download other files from this site.


Bookmark and Share
Share
Trojan

This type of behaviour covers malicious programs that delete, block, modify, or copy data, disrupt computer or network performance, but which cannot be classified under any of the behaviours identified above.

This classification also covers “multipurpose” Trojan programs, i.e. those that are capable of conducting several actions at once and which demonstrate several Trojan behaviours in a single program. This means they cannot be indisputably classified as having any single behaviour.


Other versions

Aliases

Trojan.Win32.Small.ev (Kaspersky Lab) is also known as:

  • Trojan-Downloader.Win32.Agent.ns (Kaspersky Lab)
  • Trojan: Spyre.dll (McAfee)
  • Troj/AdmDl-Gen (Sophos)
  • Heuristic.WinPE-Statistical (Panda)
  • W32/Trojan.HWK (FPROT)
  • Trojan:Win32/Renos.H (MS(OneCare))
  • Trojan.DownLoader.4218 (DrWeb)
  • Win32/Oleloa trojan (Nod32)
  • Trojan.Small.EV (BitDef7)
  • Trojan.Small!RzuVVYlvQck (VirusBuster)
  • Win32:Small-BUM [Trj] (AVAST)
  • Trojan.Win32.Small (Ikarus)
  • Generic.PJB (AVG)
  • Trojan.Desktophijack.B (NAV)
  • NseCheckFile2() returned 0x00010018 (Norman)
  • Spyre.dll (NAI)
  • Trojan.Small!RzuVVYlvQck (VirusBusterBeta)