English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Trojan-Dropper.Win32.Small.anx

Detected May 11 2006 15:37 GMT
Released Aug 21 2007 11:52 GMT
Published May 11 2006 15:37 GMT

Technical Details
Payload
Removal instructions

Technical Details

This Trojan program can be used to install other Trojans to the victim machine. The main file is a Windows PE EXE file 9405 bytes in size, packed using FSG. The unpacked file is approximately 45KB in size.


Payload

Once launched, the Trojan copies itself to the Windows system directory under a random name, with the attributes 'hidden' and 'read only'.

%System%\<random symbols>.exe

When launching, the Trojan also drops a randomly named file to the Windows system directory. This file is 4096 bytes in size, and has 'hidden', 'archive' and 'read only' attributes'.

%System%\<random symbols>.dll

This file will be detected by Kaspersky Anti-Virus as Trojan-Downloader.Win32.Small.crd.

This file will then be launched for execution, and the original file will be deleted.

The Trojan also creates the following record in the system registry:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows]
 "AppInit_DLLs"="%System%\<random symbols>.dll"

Removal instructions

Manual removal

  1. Reboot the computer in Safe Mode (at the start of the boot sequence, press and hold F8, then choose Safe Mode from the Windows boot menu.)
  2. Delete the files dropped by the Trojan:
    %System%\<random symbols>.exe
    %System%\<random symbols>.dll
  3. Change the following system registry key:

    from

    [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows]
     "AppInit_DLLs"="%System%\<random symbols>.dll"

    to the original value

     "AppInit_DLLs"=" "
  4. Update your anti-virus databases and perform a full scan of the computer. (download a trial version of Kaspersky Anti-Virus).

Bookmark and Share
Share
Trojan-Dropper

Trojan-Dropper programs are designed to secretly install malicious programs built into their code to victim computers.

This type of malicious program usually save a range of files to the victim’s drive (usually to the Windows directory, the Windows system directory, temporary directory etc.), and launches them without any notification (or with fake notification of an archive error, an outdated operating system version, etc.).

Such programs are used by hackers to:

  • secretly install Trojan programs and/or viruses
  • protect known malicious programs from being detected by antivirus solutions; not all antivirus programs are capable of scanning all the components inside this type of Trojans.

Other versions

Aliases

Trojan-Dropper.Win32.Small.anx (Kaspersky Lab) is also known as:

  • Constructor.Win32.Lasiaf.anx (Kaspersky Lab)
  • Trj/Downloader.ILA (Panda)