Home→Descriptions→Trojan-Dropper.Win32.Small.fe
| Detected | Mar 22 2004 12:56 GMT |
| Released | Mar 22 2004 12:56 GMT |
| Published | Nov 09 2007 10:26 GMT |
This Trojan is designed to install and launch other malicious programs on the victim machine without the user’s knowledge or consent. It is a Windows PE EXE file. It is 10784 bytes in size. It is packed using UPX. The unpacked file is approximately 22KB in size. It is written in C++.
When launching, the Trojan extracts the following file from its body and saves it to the Windows system directory:
This file is 8192 bytes in size. It will be detected by Kaspersky Anti-Virus as Backdoor.Win32.Thunk.f.
The Trojan also creates the following system registry keys:
[HKCU\Software\Classes\CLSID\{3F143C3A-1457-6CCA-03A7-7AA23B61E40F}\InProcServer32]
"(Default)" = "%System%\child.dll"
"ThreadingModel" = "Apartment"
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{3F143C3A-1457-6CCA-03A7-7AA23B61E40F}" = "OLE Automation Module"
If for some reason the Trojan is unable to create %System%\child.dll, it will save the malicious file as follows:
The system registry keys which the Trojan creates will correspond to this location.
The Trojan then calls this file's "load" function and ceases running.
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
[HKCU\Software\Classes\CLSID\{3F143C3A-1457-6CCA-03A7-7AA23B61E40F}\InProcServer32]
"(Default)" = "%System%\child.dll"
"ThreadingModel" = "Apartment"
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{3F143C3A-1457-6CCA-03A7-7AA23B61E40F}" = "OLE Automation Module"
Trojan-Dropper programs are designed to secretly install malicious programs built into their code to victim computers.
This type of malicious program usually save a range of files to the victim’s drive (usually to the Windows directory, the Windows system directory, temporary directory etc.), and launches them without any notification (or with fake notification of an archive error, an outdated operating system version, etc.).
Such programs are used by hackers to:
Trojan-Dropper.