Trojan-Downloader.Win32.Small.dsr
| Alert Level : | Medium |
| Discovered: | Jun 06 2006 |
| Tag: | Trojan Downloaders |
| Discoverer and Source: | http://www.kaspersky.com/ |
Malware Behavior and Technical Description
This malicious program downloads other programs from the Internet without the user's knowledge or consent and launches them on the victim machine.
The Trojan itself is a Windows PE EXE file 7026 bytes in size, packed using UPX.
Payload
Once launched, the Trojan creates a unique identified, "gagagaradio", to flag its presence in the system.
If the Trojan finds such an identifier already on the victim machine, it will terminate itself. If no such identifier is found, the Trojan will download a file via the Internet from the following:
http://81.***.3.175/cntr.php
This file will be saved to the Windows system directory as svcp.csv:
%System%\svcp.csv
This is a text file which contains encrypted links to subsequent files which will be downloaded by the Trojan. The file also contains some other information.
The Trojan downloads files from the links which it gets and saves them to the Windows system directory (%System%), adding an .exe extension. Once this is done, the Trojan launches the downloaded files for execution.
Additionally, the Trojan saves its information to the following file:
%System%\winsub.xml
The Trojan also checks for a connection to IP address 208.36.123.14, and then attempts to connect via TCP/IP port 25.
Removal Trojan-Downloader.Win32.Small.dsr instructions:
- Use Task Manager to terminate the Trojan process.
- Delete the original Trojan file (its location will depend on how the program originally penetrated the victim machine).
- Delete the following files:
%System%\svcp.csv %System%\winsub.xml
- Update your antivirus databases and perform a full scan of the
computer (download a trial version of Kaspersky Anti-Virus).
Need help? Live computer support via remote at SupportSpace
.Help with printer problems, windows, hardware, software, spyware removal and more. - Go Now!

