Win32/TrojanDownloader.Small.PSL [Threat Name] go to Threat

Win32/TrojanDownloader.Small.PSL [Threat Variant Name]

Category trojan
Size 3072 B
Detection created Feb 02, 2015
Detection database version 11111
Aliases Packed.Win32.Katusha.o (Kaspersky)
Short description

Win32/TrojanDownloader.Small.PSL is a trojan which tries to download other malware from the Internet.

Installation

When executed, the trojan copies itself into the following location:

  • %appdata%\­Servicer.exe

In order to be executed on every system start, the trojan sets the following Registry entry:

  • [HKEY_CURRENT_USER\­Software\­Microsoft\­Windows\­CurrentVersion\­Run]
    • "System Service host" = "%appdata%\­Servicer.exe !!!!"
Other information

The trojan contains a URL address.


It tries to download a file from the address.


The file is stored in the following location:

  • %temp%\­qazxsw003.exe

The file is then executed. The HTTP protocol is used.

Please enable Javascript to ensure correct displaying of this content and refresh this page.