Virus Encyclopedia

Computer Virus Encyclopedia

Trojan-Downloader.Win32.Small.dsr

Alert Level : Medium
Discovered: Jun 06 2006
Tag:
Discoverer and Source: http://www.kaspersky.com/

Malware Behavior and Technical Description

This malicious program downloads other programs from the Internet without the user's knowledge or consent and launches them on the victim machine.

The Trojan itself is a Windows PE EXE file 7026 bytes in size, packed using UPX.

Payload

Once launched, the Trojan creates a unique identified, "gagagaradio", to flag its presence in the system.

If the Trojan finds such an identifier already on the victim machine, it will terminate itself. If no such identifier is found, the Trojan will download a file via the Internet from the following:

http://81.***.3.175/cntr.php

This file will be saved to the Windows system directory as svcp.csv:

%System%\svcp.csv

This is a text file which contains encrypted links to subsequent files which will be downloaded by the Trojan. The file also contains some other information.

The Trojan downloads files from the links which it gets and saves them to the Windows system directory (%System%), adding an .exe extension. Once this is done, the Trojan launches the downloaded files for execution.

Additionally, the Trojan saves its information to the following file:

%System%\winsub.xml

The Trojan also checks for a connection to IP address 208.36.123.14, and then attempts to connect via TCP/IP port 25.

Removal Trojan-Downloader.Win32.Small.dsr instructions:

  1. Use Task Manager to terminate the Trojan process.
  2. Delete the original Trojan file (its location will depend on how the program originally penetrated the victim machine).
  3. Delete the following files:
    %System%\svcp.csv
    %System%\winsub.xml
  4. Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).

    Need help? Live computer support via remote at SupportSpace.Help with printer problems, windows, hardware, software, spyware removal and more. - Go Now!

Site Map
About Us