Win32/TrojanDownloader.Small.AAP [Threat Name] go to Threat

Win32/TrojanDownloader.Small.AAP [Threat Variant Name]

Category trojan
Size 8704 B
Detection created Aug 01, 2005
Detection database version 0.11185
Aliases Backdoor:Win32/Jukbot.B (Microsoft)
  Trojan.Rincux.AW (BitDefender)
Short description

Win32/TrojanDownloader.Small.AAP is a trojan which tries to download other malware from the Internet.

Installation

When executed, the trojan copies itself into the following location:

  • %system%\­wmiprvze.exe

The trojan registers itself as a system service using the following name:

  • dddddd

This causes the trojan to be executed on every system start.

Other information

Win32/TrojanDownloader.Small.AAP is a trojan which tries to download other malware from the Internet.


The trojan contains a list of (5) URLs.


It tries to download several files from the addresses.


The files are stored in the following locations:

  • %system%\­1.exe
  • %system%\­2.exe
  • %system%\­3.exe
  • %system%\­4.exe
  • %system%\­5.exe

The files are then executed. The HTTP protocol is used.


The trojan then removes itself from the computer.


The trojan executes the following command:

  • cmd.exe /c del %malwarefilepath% > nul

Please enable Javascript to ensure correct displaying of this content and refresh this page.