Trojan-Downloader.Win32.Tiny.al

tag:Trojan   Downloaders  

Once launched, the Trojan creates a unique identifier to flag its presence in the system and prevent it from being repeatedly launched. While downloading files, the Trojan remains in memory as a process. The process will have the same name as that of the Trojan executable file.

The Trojan then tries to establish a connection with the remote malicious user's HTTP server:

http://goldenfreehost.com/****der.php?l=0419

The Trojan downloads a file which contains a list of URLs.

This file will be saved to the Windows temporary catalogue as "list":

%TEMP%\list

The Trojan then attempts to download files from the URLs listed in this file. These files will also be saved to the Windows temporary directory, and then launched for execution.

  1. Use Task Manager to delete the Trojan process from memory.
  2. Delete the original Trojan file (the location of this file will depend on how the victim machine was infected).
  3. Delete all files downloaded by the Trojan from the Windows temporary directory.
  4. Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).

This Trojan program downloads files via the Internet without the knowledge or consent of the user. The Trojan itself is a Windows PE EXe file 3072 bytes in size.

Payload

©Virus-Encyclopedia.com All Rights Reserved.