Once launched, the Trojan establishes a connection on port 3200 to 64.**.228.66 and downloads another Trojan, which will be detected by Kaspersky Anti-Virus as Trojan-Downloader.Win32.Small.dcj. This file will be saved to the same folder as the original Trojan file, and launched for execution.
- Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
- Delete a file named
This Trojan downloads files via the Internet without the user’s knowledge or consent. It is a Windows PE EXE file. The file is 3072 bytes in size. It is not packed in any way.
Payload

Subscribe
Hot Articles