|
Trojan.Downloader.Small.DP Trojan Downloader Information
| Name: |
Trojan.Downloader.Small.DP |
| Category: |
Trojan Downloader |
| Advice: |
Remove |
| Risk: |
Severe Risk
Severe threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction and exploits are in the wild. There exists a high possibility of potential system damage or security flaw. Attacker has complete control over your computer or install new software on your machine. |
| Description:
|
Trojan.Downloader.Small.DP is a Trojan downloader for the Windows platform.
When run the Trojan attempts to download files from the Internet to the files C:t.exe, C:n.exe or C:m.exe and run them.
The Trojan also tries to create the following registry entries so as to run itself on computer startup:
HKCUSoftwareMicrosoftWindowsCurrentVersionRunOnce
Local runole service
%SYSTEM%srvc32.exe
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunOnce
Local runole service
%SYSTEM%srvc32.exe
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun
Local runole service
%SYSTEM%srvc32.exe
In order to stealth itself, the Trojan also attempts to inject itself into the Windows Explorer process.
|
| Signatures:
|
process: srvc32.exe: MD5 Hash: 4e74aba4dc755acea23.. |
| Type: |
Trojan Downloader - A Trojan software is any software on a user's computer that the user is not aware or intentionally installed. Most Trojan software is designed to perform some sort of actions that could jeopardize the user's security or privacy. |
Top Trojan Downloader Visited Pages:
TrojanDownloader:Win32/Small.ADO - 339 visits
Trojan.Downloader.Slvr - 202 visits
Trojan.Downloader.Small.ADR - Alias: TrojanDownloader:Win32/Small.ADR - 62 visits
Peper - Alias: Backdoor.VB.nb, pepar trojan, Quadro - 56 visits
Trojan.Downloader.U - 48 visits
Bagle.HP - 47 visits
Bagle.BV - 46 visits
Trojan.Dropper.AV - Alias: Troj/Dropper-AV - 45 visits
Trojan.Downloader.Small.HS - Alias: TrojanDownloader:Win32/Small.HS - 42 visits
eXact.Downloader - 42 visits
Random Trojan Downloader Pages:
Winshow.AQ
Trojan.Downloader.Agent.KB - Alias: TrojanDownloader:Win32/Agent.KB
Delf.DH
Trojan.Downloader.CR64Loader - Alias: TrojanDownloader:Win32/Agent.DE, Miniclip, CR64Loader
Trojan.Downloader.kwdstd
SysComDloader - Alias: HereToFind, Here2Find, XXX My PORNO, TrojanDownloader.Win32.Small.zq
Agent.ML
Generic
Trojan.Downloader.Agent.BC - Alias: TrojanDownloader:Win32/Agent.BC
Trojan.Downloader.kaka
|