Home→Descriptions→Trojan-Dropper.Win32.Small.anx
| Detected | May 11 2006 15:37 GMT |
| Released | Aug 21 2007 11:52 GMT |
| Published | May 11 2006 15:37 GMT |
This Trojan program can be used to install other Trojans to the victim machine. The main file is a Windows PE EXE file 9405 bytes in size, packed using FSG. The unpacked file is approximately 45KB in size.
Once launched, the Trojan copies itself to the Windows system directory under a random name, with the attributes 'hidden' and 'read only'.
When launching, the Trojan also drops a randomly named file to the Windows system directory. This file is 4096 bytes in size, and has 'hidden', 'archive' and 'read only' attributes'.
This file will be detected by Kaspersky Anti-Virus as Trojan-Downloader.Win32.Small.crd.
This file will then be launched for execution, and the original file will be deleted.
The Trojan also creates the following record in the system registry:
Manual removal
from
to the original value
Trojan-Dropper programs are designed to secretly install malicious programs built into their code to victim computers.
This type of malicious program usually save a range of files to the victim’s drive (usually to the Windows directory, the Windows system directory, temporary directory etc.), and launches them without any notification (or with fake notification of an archive error, an outdated operating system version, etc.).
Such programs are used by hackers to:
Trojan-Dropper.